All tools

DKIM Checker - Test and Verify DKIM Records

Is your entry valid? Check the selector and signature setup before email providers judge you.

Find it in your email provider's DKIM settings (e.g. 'google', 'mail')

Enter a domain and optional selector - e.g. yourdomain.com with selector google

DKIM record found

Whether the selector resolves in DNS

Public key

Valid signing key published for your domain

Record format

Syntax issues that break verification

No account required · Free · Results in under 1s

What is a DKIM checker?

Records, keys, and authentication in plain terms

DKIM (DomainKeys Identified Mail) adds a digital signature to every email your domain sends. Receiving servers look up the DKIM record in DNS, verify the signature with the public key, and decide if the message is genuine. A broken entry, a rotated credential, or a wrong selector can fail that test silently - and hurt deliverability.

This free DKIM checker looks up the entry for any domain and selector, validates the credentials, and shows exactly what providers see. Use this record checker after DNS changes, credential rotation, or when a new email service sends on your behalf, so email authentication keeps working.

Run a one-time test before campaigns or migrations. Add the domain to TotalSiteControl monitoring for alerts when the entry, the SPF record, or the DMARC record changes or stops resolving.

Get 30 monitors FREE

Start free monitoring with email alerts. No credit card required.

How to run the DKIM test in three steps

Review the setup for any sender in under a minute - no account needed.

  1. Enter the domain and selector

    Type the domain name that sends the email, for example yourdomain.com, and the DKIM selector your provider gave you, such as google, s1, or k1. The selector points to the right DNS entry.

  2. Run the check

    Click Check. We query DNS for the entry at selector._domainkey.example.com, parse the credentials, and verify their format and flags. The result shows the raw value.

  3. Read the result

    See whether the DKIM record and its key are valid, which tags are set, and whether the credentials parse. Fix mistyped entries at the DNS provider, then test again to confirm DMARC passes.

Typical DKIM issues and solutions

What breaks deliverability - and how to fix it before email bounces.

DKIM record not found

DNS returns nothing for the selector, so receiving servers cannot verify the signature. Email drifts to spam or bounces, and nobody gets told.

Publish the record at the right name

Copy the exact value from your provider and add it as a TXT entry at selector._domainkey.example.com. Wait for DNS to propagate, then test again.

Credential mismatch after rotation

The sending service signs with a new private key, but DNS still serves the old one. Every signature fails verification until DNS catches up.

Sync the credentials in DNS

Update the entry with the new credentials from the provider, and keep the old selector live during the transition window if supported.

DMARC alignment fails

The DMARC record demands alignment, but the DKIM signature covers another zone than the visible From address. Authentication fails even though the entry itself is valid.

Align the zones

Sign for the same zone users see in the From header, or review the DMARC policy and relax alignment deliberately.

Sender policy and signing disagree

Authorization passes from one host while the signature comes from another, and forwarding breaks both. Mixed SPF DKIM results lower trust.

Bring both into agreement

Authorize the same sending hosts that sign the mail, then verify both after every DNS change - DMARC depends on it.

What you get with monitoring

Comprehensive data

DKIM, DMARC, and lookup history in one place.

Trusted & accurate

Tests run from our servers - the same DNS path receivers use.

Fast & easy

Turn a one-off DKIM lookup into monitoring in under a minute.

Global coverage

External probes so internal network blind spots do not hide issues.

Instant alerts

Email and Telegram alerts when an entry breaks or stops resolving.

30 monitors free

Start free - no credit card required to begin monitoring.

Get 30 monitors FREE

Start free monitoring with email alerts. No credit card required.

DKIM email tips

Quick habits that keep entries valid and email out of spam.

Tip #1 Keep selector and entry in sync

When a provider rotates credentials, publish the new DKIM record the same day. A stale entry fails every signature verification.

Tip #2 Test SPF DKIM together

Sender policy and signing fail independently. Verify both after every DNS edit - and test the policy too.

Show more tips Show less tips
Tip #3 Watch DMARC reports

DMARC aggregate reports show who signs for your domain and how DMARC judges each source. Review them monthly to spot unauthorized senders before they hurt your email reputation.

Tip #4 Use one domain name in From

Align the signing domain with the visible From zone so DMARC alignment passes cleanly.

Tip #5 Test before big campaigns

Run a check on the exact DKIM selector the campaign uses. A missing entry is cheaper to fix before the email blast goes out.

Frequently asked questions

What does this DKIM check show?

It looks up the entry for your zone and selector, validates the credentials, and shows every tag - the same data providers use to verify the signature.

Is this DKIM check free?

Yes. Check any public zone and selector instantly - no signup, no credit card, no limit on one-off lookups. Monitoring alerts are also free to start.

What is a DKIM selector?

The selector is a label, such as google or s1, that tells receivers which DKIM record to look up. The full DNS name is selector._domainkey.example.com.

Why does my DKIM signature fail?

Common causes: the entry is missing, credentials were rotated without updating DNS, or the DKIM selector is mistyped. Re-publish the exact value from your provider and test again.

What is the difference between SPF DKIM and DMARC?

SPF authorizes sending hosts, DKIM signs each message with credentials, and the DMARC record tells receivers what to do when tests fail. DMARC works best when both agree.

How do I add a DKIM record?

Copy the TXT value from your provider and add it in DNS at selector._domainkey.example.com. Propagation usually takes minutes; verify with a fresh test before you start sending.

Can I check DKIM for another domain?

Yes - the entry is public DNS data. Enter any domain name and selector to see how providers sign email for it - useful before trusting a newsletter or vendor.

How often should I check DKIM records?

After every DNS change, credential rotation, or new sending service. For production senders, automated monitoring is safer - it catches a broken entry before recipients do. DMARC failures often follow, so watch both.

What is inside a DKIM record?

Tags like v=DKIM1, k=rsa, and p= holding the key itself. An empty p= means the key was revoked. The tool parses each tag and flags problems.

Does DKIM affect deliverability?

Yes. A valid signature builds sender reputation, while failed tests push email toward spam. DKIM also feeds DMARC, so a broken entry weakens the whole authentication chain.

What is DMARC alignment?

Alignment means the signing domain (or the sender policy zone) matches the From zone. The DMARC record sets strict or relaxed alignment for each mechanism, and DMARC reports show where it breaks.

Should I rotate DKIM keys?

Periodically, yes. Publish the new credentials in the entry before switching signers, keep the old DKIM selector live during the overlap, then retire it.

What is a DKIM signature?

A cryptographic value the sender computes over the message with a private key. Receivers recompute it using the public key from the entry to prove the email was not altered in transit.

Do I need SPF DKIM and DMARC together?

For strong email authentication, yes. Sender policy alone breaks on forwarding, DKIM alone cannot stop spoofed From zones, and DMARC without both has nothing to evaluate. Set SPF DKIM first, then publish a DMARC policy.

Does monitoring cover DMARC too?

Yes - monitors can watch the entry and the DMARC record together, with alerts when either changes or stops resolving. Track every monitored zone from one dashboard.

Never miss a broken DKIM record again

Free monitoring with alerts when your entry, SPF record, or DMARC policy changes - for every zone you send email from.

Start Monitoring Free