Is DKIM configured for your selector - verify the public key before signed mail fails.
Find it in your email provider's DKIM settings (e.g. 'google', 'mail')
We'll send a summary for your target only. Unsubscribe anytime.
Whether the selector resolves in DNS
Valid signing key published for your domain
Syntax issues that break verification
No account required · Free · Results in under 1s
Email signing records explained
When DKIM signing breaks, receivers cannot verify message integrity - authenticated mail fails and inbox placement drops, often after a provider migration or key rotation.
A DKIM checker looks up the public key at selector._domainkey.yourdomain.com and validates the record your email provider published. Enter the selector your ESP documents for accurate results.
Run a free DKIM check after configuring outbound mail or rotating keys. Add domains to TotalSiteControl monitoring for alerts when signing records change or disappear.
Start free monitoring with email alerts. No credit card required.
Validate DKIM DNS records for a selector in under a minute - no account needed.
Provide the signing domain and the DKIM selector your mail provider gave you (for example s1 or google).
Click the check button. We look up the selector._domainkey TXT record and report whether a key is published.
Confirm the public key exists and matches what the provider expects. Fix DNS typos, then re-check after TTL.
Why signatures fail even when SPF looks fine.
Receivers cannot find a public key. DKIM verification fails for that selector.
Copy the exact selector host and value from your ESP, wait for DNS, then re-run the DKIM check.
You check default while mail signs with another selector. The tool shows empty even though production works, or the reverse.
Open a raw message header, find s= in DKIM-Signature, and check that selector.
Provider moved to a new key while DNS still publishes the old one.
Replace the selector record with the new value, verify both old and new during overlap if required, then remove the obsolete key.
Certificate, DNS, and reachability history in one place.
Checks run from our servers - the same path users hit.
Turn a one-off check into monitoring in under a minute.
External probes so internal network blind spots do not hide issues.
Email and Telegram when something fails or is about to expire.
Start free - no credit card required to begin monitoring.
Start free monitoring with email alerts. No credit card required.
Selectors are easy to mistype and hard to notice.
Headers tell you which selector is signing production mail right now.
Transactional and marketing tools often use different selectors on the same domain.
Re-check too early and you may still see the old key from resolver cache.
Unexpected selector edits break authentication. Alerts catch silent drift.
It looks up the DKIM DNS record for a domain and selector, validating the public key used to verify cryptographically signed email.
Yes. Enter a domain and selector for instant results - no signup, no credit card, and no limit on one-off checks.
A label that identifies which DKIM public key to use. It's part of the DNS lookup name, e.g. google._domainkey.yourdomain.com.
Check your email provider documentation - Google uses google, Microsoft often uses selector1, and many ESPs use default.
Wrong selector, a missing DNS record, or a key that has not propagated yet after setup. Confirm the exact record your provider published.
Yes - SPF and DKIM solve different problems. Use both plus DMARC for full email authentication.
Your email provider generates a public key. Add the TXT record they supply at selector._domainkey.yourdomain.com, then verify here.
After email provider changes or key rotation. Monitoring alerts when DKIM records change or disappear.