Check your DKIM record

With DKIM, your emails carry a signature that proves they came from you and weren't changed along the way. Use this tool to check the DKIM key published for your domain.

Commands

Frequently asked questions

How to use the DKIM check

Enter the domain and a selector, then run the check. The selector tells us which key to look up, since a domain publishes a separate one for every service that sends in its name. Your newsletter tool, your helpdesk, and your mail server each have their own.

For DMARC or SPF questions, use the DMARC check and the SPF check.

What is a DKIM selector, and where do I find mine?

A selector is a name that points to one specific key. Your domain can publish many, because each service signing mail for you gets its own, and the record lives at selector._domainkey.yourdomain.com.

Text
google._domainkey.example.com       TXT    "v=DKIM1; k=rsa; p=MIIBIjANBgkq..."
selector1._domainkey.example.com    TXT    "v=DKIM1; k=rsa; p=MIIBIjANBgkq..."

To find yours, open an email sent from the domain, view the source, and read s= in the DKIM-Signature header. Common ones are google for Google Workspace, selector1 and selector2 for Microsoft 365, and k1 for several marketing platforms.

How do I know if DKIM passed?

This check tells you whether a valid key is published, which is the part you control. Whether a given message passed is decided by the receiving provider when it arrives. Open the message in your mailbox, view the source, and look for dkim=pass in the Authentication-Results header. For a view across all your mail rather than one message at a time, you need DMARC reports.

Start monitoring your email traffic today!

Ready to gain full visibility into your email traffic? Sign up to start monitoring your emails and take control of your domain’s security today.