Is your entry valid? Check the selector and signature setup before email providers judge you.
Find it in your email provider's DKIM settings (e.g. 'google', 'mail')
We'll send a summary for your target only. Unsubscribe anytime.
Whether the selector resolves in DNS
Valid signing key published for your domain
Syntax issues that break verification
No account required · Free · Results in under 1s
Records, keys, and authentication in plain terms
DKIM (DomainKeys Identified Mail) adds a digital signature to every email your domain sends. Receiving servers look up the DKIM record in DNS, verify the signature with the public key, and decide if the message is genuine. A broken entry, a rotated credential, or a wrong selector can fail that test silently - and hurt deliverability.
This free DKIM checker looks up the entry for any domain and selector, validates the credentials, and shows exactly what providers see. Use this record checker after DNS changes, credential rotation, or when a new email service sends on your behalf, so email authentication keeps working.
Run a one-time test before campaigns or migrations. Add the domain to TotalSiteControl monitoring for alerts when the entry, the SPF record, or the DMARC record changes or stops resolving.
Start free monitoring with email alerts. No credit card required.
Review the setup for any sender in under a minute - no account needed.
Type the domain name that sends the email, for example yourdomain.com, and the DKIM selector your provider gave you, such as google, s1, or k1. The selector points to the right DNS entry.
Click Check. We query DNS for the entry at selector._domainkey.example.com, parse the credentials, and verify their format and flags. The result shows the raw value.
See whether the DKIM record and its key are valid, which tags are set, and whether the credentials parse. Fix mistyped entries at the DNS provider, then test again to confirm DMARC passes.
What breaks deliverability - and how to fix it before email bounces.
DNS returns nothing for the selector, so receiving servers cannot verify the signature. Email drifts to spam or bounces, and nobody gets told.
Copy the exact value from your provider and add it as a TXT entry at selector._domainkey.example.com. Wait for DNS to propagate, then test again.
The sending service signs with a new private key, but DNS still serves the old one. Every signature fails verification until DNS catches up.
Update the entry with the new credentials from the provider, and keep the old selector live during the transition window if supported.
The DMARC record demands alignment, but the DKIM signature covers another zone than the visible From address. Authentication fails even though the entry itself is valid.
Sign for the same zone users see in the From header, or review the DMARC policy and relax alignment deliberately.
Authorization passes from one host while the signature comes from another, and forwarding breaks both. Mixed SPF DKIM results lower trust.
Authorize the same sending hosts that sign the mail, then verify both after every DNS change - DMARC depends on it.
DKIM, DMARC, and lookup history in one place.
Tests run from our servers - the same DNS path receivers use.
Turn a one-off DKIM lookup into monitoring in under a minute.
External probes so internal network blind spots do not hide issues.
Email and Telegram alerts when an entry breaks or stops resolving.
Start free - no credit card required to begin monitoring.
Start free monitoring with email alerts. No credit card required.
Quick habits that keep entries valid and email out of spam.
When a provider rotates credentials, publish the new DKIM record the same day. A stale entry fails every signature verification.
Sender policy and signing fail independently. Verify both after every DNS edit - and test the policy too.
DMARC aggregate reports show who signs for your domain and how DMARC judges each source. Review them monthly to spot unauthorized senders before they hurt your email reputation.
Align the signing domain with the visible From zone so DMARC alignment passes cleanly.
Run a check on the exact DKIM selector the campaign uses. A missing entry is cheaper to fix before the email blast goes out.
It looks up the entry for your zone and selector, validates the credentials, and shows every tag - the same data providers use to verify the signature.
Yes. Check any public zone and selector instantly - no signup, no credit card, no limit on one-off lookups. Monitoring alerts are also free to start.
The selector is a label, such as google or s1, that tells receivers which DKIM record to look up. The full DNS name is selector._domainkey.example.com.
Common causes: the entry is missing, credentials were rotated without updating DNS, or the DKIM selector is mistyped. Re-publish the exact value from your provider and test again.
SPF authorizes sending hosts, DKIM signs each message with credentials, and the DMARC record tells receivers what to do when tests fail. DMARC works best when both agree.
Copy the TXT value from your provider and add it in DNS at selector._domainkey.example.com. Propagation usually takes minutes; verify with a fresh test before you start sending.
Yes - the entry is public DNS data. Enter any domain name and selector to see how providers sign email for it - useful before trusting a newsletter or vendor.
After every DNS change, credential rotation, or new sending service. For production senders, automated monitoring is safer - it catches a broken entry before recipients do. DMARC failures often follow, so watch both.
Tags like v=DKIM1, k=rsa, and p= holding the key itself. An empty p= means the key was revoked. The tool parses each tag and flags problems.
Yes. A valid signature builds sender reputation, while failed tests push email toward spam. DKIM also feeds DMARC, so a broken entry weakens the whole authentication chain.
Alignment means the signing domain (or the sender policy zone) matches the From zone. The DMARC record sets strict or relaxed alignment for each mechanism, and DMARC reports show where it breaks.
Periodically, yes. Publish the new credentials in the entry before switching signers, keep the old DKIM selector live during the overlap, then retire it.
A cryptographic value the sender computes over the message with a private key. Receivers recompute it using the public key from the entry to prove the email was not altered in transit.
For strong email authentication, yes. Sender policy alone breaks on forwarding, DKIM alone cannot stop spoofed From zones, and DMARC without both has nothing to evaluate. Set SPF DKIM first, then publish a DMARC policy.
Yes - monitors can watch the entry and the DMARC record together, with alerts when either changes or stops resolving. Track every monitored zone from one dashboard.