Home › Free tools

DKIM Record Checker

DKIM lives at selector._domainkey.yourdomain.com. Enter the domain and, if you know it, the selector. Otherwise the checker tries the selectors used by Google Workspace, Zoho, Microsoft 365, Amazon SES, SendGrid, Mailgun, Lark and Yahoo, and tells you which one is published and whether the key is valid.

What is a selector?

A label the sender chooses so a domain can hold several keys. Google uses google, Zoho uses zmail, Microsoft uses selector1 and selector2, SendGrid uses s1 and s2. The record sits at selector._domainkey.domain.

Why does the key length matter?

Receivers expect at least 1024-bit keys and prefer 2048. Short keys are treated as unsigned. Most providers now issue 2048-bit keys; regenerate if yours is 1024.

My key is published but mail still fails DKIM

The provider must be signing outgoing mail with that selector. In Google Admin and Zoho Admin there is a separate Enable or Start authentication step after the DNS record is added.

Frequently asked questions

Do I need DKIM for cold email?

Yes. Gmail and Yahoo require DKIM for bulk senders and treat its absence as a strong spam signal for everyone else. It is also what DMARC usually aligns on.

Can one domain have several DKIM records?

Yes, one per selector. Each sending service gets its own selector, so Google and SendGrid can both sign for the same domain.

What does t=y mean?

Testing mode. Some receivers treat signatures from a t=y key as unverified. Remove the flag once signing works.

Why does the checker look at CNAMEs?

Microsoft 365, SendGrid and Mailgun publish DKIM as CNAME records that point to the provider's key. The checker follows them.

Records right? Now build the reputation.

Connect the mailbox to the free warm-up service: it sends, replies and rescues from Spam on a shared warm-up network (or a private pool per account), and tells you when you are ready for outbound.

Start free

More free tools