DKIM record checker
Updated
DKIM keys live at selector._domainkey.yourdomain.com, so you need both the domain and the selector. If you do not know it, see the FAQ below.
Looks up public DNS only. Nothing you enter is stored.
What the checker tests
- That a record exists at
selector._domainkey.domain, and whether it is reached through a CNAME - That the
p=public key is present. An emptyp=means the key was revoked - The approximate RSA key size. 2048 bits is the current recommendation, and 1024 is flagged as weak
- The
t=ytesting flag, which tells receivers not to treat failures as meaningful
It checks the DNS record, not an actual message signature. To confirm real mail is signed, send yourself a message and read the Authentication-Results header for dkim=pass.
Inboxili's DKIM records
When you add a domain in the Deliverability Center you get three CNAME records of the form token._domainkey.yourdomain.com pointing at token.dkim.amazonses.com. Enter one of those tokens as the selector to check it.
If the check fails
- No record found: check the selector spelling and the exact host. Some DNS panels append the domain automatically, which produces
s1._domainkey.example.com.example.com. - CNAME found, no key: the CNAME target is wrong or the provider has not finished setting up the key.
- Empty p=: the key was revoked. Generate a new one with your provider.
More background: SPF, DKIM and DMARC explained.
Frequently asked questions
- How do I find my DKIM selector?
- Open a message you sent, view the original source, and find the DKIM-Signature header. The s= value is the selector and d= is the domain. Your email provider's setup screen also lists it.
- My provider gave me a CNAME. Is that right?
- Yes. Many providers, including Amazon SES, ask you to publish a CNAME so they can rotate keys. The checker follows it and reports the key found at the target.
Need reliable email delivery? Try Inboxili
Create a workspace, verify a domain, and make your first API call.