DKIM Record Checker
Instantly check any domain's DKIM selectors and detect the mail platform in use.
Need to monitor this across every client domain you manage? ActiScan does bulk scanning, scoring, and white-labeled reporting for MSPs.
How to Use the DKIM Checker
Enter a domain
No http:// prefix – just the domain itself (e.g. company.com).
Click Check
ActiScan detects your mail platform from MX records, then probes common and platform-specific DKIM selector names over DNS.
Read the result
A pass/warn/fail status, the mail platform detected, and every selector that resolved a real key.
What Your Result Means
2+ selectors foundPassMultiple selectors resolved to a real DKIM key. That usually means your primary mail platform and at least one third-party sender (a marketing tool, a transactional-email API) each have their own key published and active.
1 selector foundWarnDKIM is active for at least one sender, but if you also send mail through other platforms, each one needs its own key – a single resolved selector doesn't confirm the others are covered.
No selectors foundFailNone of the common selector names resolved a key for the detected platform. That usually means DKIM hasn't been enabled yet – though it can also mean DKIM is live under a nonstandard selector this scan didn't guess.
What is a DKIM Record?
DKIM (DomainKeys Identified Mail) adds a cryptographic signature to outgoing email. Your mail server signs a hash of the message with a private key and attaches it as a DKIM-Signature header, which names the sending domain (d=) and a selector (s=). Receiving servers extract both, fetch the matching public key from DNS, and verify the signature matches – proof the message wasn't altered in transit and really came from a server authorized to send for that domain.
A selector is just a label that lets a domain publish more than one DKIM key at once – one per sending platform, or a new one during key rotation – each at its own DNS name. Because the selector is chosen by whoever sets up DKIM (Google Workspace defaults to "google", Microsoft 365 to "selector1"/"selector2", and third-party senders often pick their own fixed name), there's no single fixed record to check the way there is for SPF or DMARC – which is why this checker probes a list of likely selector names instead of asking you to supply one.
Key length matters too: 1024-bit RSA keys are considered weak and increasingly rejected by receiving servers, while 2048-bit is the current standard – it's what ActiScan's own DKIM generator produces.
DKIM Record Examples
Standard RSA record
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC7...
The typical format – protocol version, key type, and the base64-encoded public key. checkDKIM matches this via the v=DKIM1 or k=rsa tags.
Bare public-key record
p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC7...
Some senders publish only the p= tag, since v= and k= are optional with implied defaults. checkDKIM specifically matches a real p= tag for exactly this case.
Testing-mode record
v=DKIM1; k=rsa; t=y; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC7...
The t=y flag marks a freshly-rotated key as being tested – useful while you confirm a new key signs correctly before removing the flag.
Need to build your own? Use the free DKIM generator.
DKIM Record Tags Explained
| Tag | What it does | Example | Required? |
|---|---|---|---|
| v | Protocol version. Should be the first tag if present. | v=DKIM1 | Optional (default: DKIM1) |
| k | Key type. | k=rsa | Optional (default: rsa) |
| p | The public key, base64-encoded. An empty value revokes the key. | p=MIGfMA0GCSq... | Required |
| h | Acceptable hash algorithms for the signature. | h=sha256 | Optional |
| s | Service type this key applies to. | s=email | Optional (default: *) |
| t | Flags: y (testing mode) or s (strict subdomain match). | t=y | Optional |
| n | Human-readable notes for administrators. | n=Rotated 2026-08 | Optional |
How to Find Your DKIM Record Manually
You need the selector first – check your mail platform's DKIM setup page, or look at the s= tag in a DKIM-Signature header from a message you've sent (view the raw source/headers). Then:
Using nslookup
nslookup -type=TXT default._domainkey.yourdomain.com
Using dig
dig TXT default._domainkey.yourdomain.com
Replace default with your actual selector.
Next Steps After Your Check
No record found?
On Google Workspace or Microsoft 365? Enable DKIM in that provider's admin console – it generates and manages the key for you. Self-hosting your own mail server? Generate a real keypair instead.
DKIM Generator →Only one selector found?
ActiScan tracks every sending platform you use and flags any that are missing DKIM.
Start free →Want ongoing monitoring?
ActiScan scans on a schedule and alerts you when a DKIM key disappears or a new sending platform shows up unprotected – across every domain you manage.
Start free →Frequently Asked Questions
Is this DKIM checker free?
Yes – check any domain's DKIM selectors for free, no signup required.
Do I need to know my selector to use this checker?
No. It automatically probes common selector names plus ones specific to the mail platform it detects (Google Workspace, Microsoft 365, Mimecast, Proofpoint) and popular third-party senders. If your setup uses a custom selector outside that list, it won't be found this way.
Why does it say "no selectors found" when I know DKIM is set up?
Your DKIM key is probably published under a selector this scan doesn't guess. Look at the DKIM-Signature header of a message you've sent – the s= tag there is the real selector – then check it manually (see below).
Why doesn't DKIM work like the SPF or DMARC checkers?
SPF and DMARC live at fixed, well-known DNS names (the domain root, and _dmarc). DKIM doesn't – it lives at a selector-specific name chosen when DKIM was configured, so there's no single fixed place to look, only informed guesses.
Where is a DKIM record published?
As a TXT record at <selector>._domainkey.yourdomain.com – for example, a key published under the selector "google" for example.com lives at google._domainkey.example.com.