Free DKIM Checker.
Check your domain’s DKIM record in seconds. Verify the selector, confirm the public key, and catch DNS misconfigurations before they affect email deliverability.
DKIM Checker.
How does DKIM Checker work?
Enter your domain and DKIM selector, then click Check. We look up the DKIM TXT record at {selector}._domainkey.{domain} and display the result in a readable format—so you can confirm the record exists and is configured correctly.
What is DKIM?
DKIM (DomainKeys Identified Mail) adds a cryptographic signature to outbound emails. Receiving mail servers use your DKIM DNS record (public key) to verify the message wasn’t altered and that it was signed by an authorized sender for your domain.
What is a DKIM selector?
A selector is a label (like google or selector1) that lets you publish multiple DKIM keys for the same domain—useful for different email providers, key rotation, and safer migrations.
When should you check DKIM?
- After enabling DKIM in Google Workspace, Microsoft 365, or an email-sending tool
- When DMARC reports show DKIM failures
- If emails start landing in spam or get rejected
- After DNS provider changes or a nameserver migration
Get 50 monitors with 5-minute checks totally FREE.
Try UpTimeRobot - the world's leading website monitoring service!
Start monitoring for freeFrequently asked questions.
Where do I find my DKIM selector?
Your email provider or sending platform shows it in the DKIM setup screen. Common selectors include
google,selector1,selector2,default, or a custom value your provider generates.Why does the DKIM checker say “record not found”?
Most often: the selector is wrong, the record was added to the wrong DNS provider (not your active nameservers), or it was created under the wrong hostname (it must be
{selector}._domainkey.{domain}).Can I have multiple DKIM records for one domain?
Yes. You can publish multiple selectors for different providers or for key rotation. Each selector has its own DKIM record under
_domainkey.{domain}.What DKIM key length should I use—1024 or 2048?
2048-bit keys are generally preferred when supported. Some providers still use 1024-bit keys depending on setup constraints—follow your provider’s guidance.
My DKIM record exists—why is DKIM still failing?
Common causes include sending from a different domain than you checked, using a different selector than the one used in signatures, DNS still caching old values, or your provider not actually signing outgoing mail yet.
What’s the difference between DKIM and DMARC?
DKIM signs email. DMARC tells receivers what to do when SPF/DKIM fail and checks alignment with the visible “From” domain.
How long do DKIM DNS changes take to propagate?
It depends on TTL and caching. Many updates appear quickly, but some resolvers may keep old values until their cache expires.
Get your FREE account now, 50 monitors included!
Try UpTimeRobot - the world’s leading website monitoring service!
Start monitoring for free