Your browser asks Google Public DNS directly for the domain’s public records. Nothing is sent to this site and nothing is stored; only an anonymous count of checks is kept.
What DKIM does
DKIM signs every outgoing email with a private key. The matching public key is published in DNS at selector._domainkey.yourdomain. The receiving server uses it to check that the message was not altered and really came from your domain.
How to find your selector
- Send a message from your business address to a personal Gmail address.
- Open it and choose “Show original”.
- In the DKIM-Signature header, read the s= value (that is the selector).
- Type it in the box above.
Common selectors
- Microsoft 365: selector1 and selector2 (CNAME records).
- Google Workspace: google, by default.
- SendGrid: s1 and s2.
- Mailchimp: k1, k2, and k3.
- Others: default, dkim, mail, selector, mandrill, smtp.
Key size
1024-bit keys still exist, but 2048 bits is recommended. The tool estimates the size from the length of the public key: it is an estimate, not an exact measurement.
Frequently asked questions
Why is my DKIM a CNAME?
Microsoft 365 and some other providers ask you to publish a CNAME that points to their key, so they can rotate it themselves.
Does DKIM alone make DMARC pass?
Yes, if the signature passes and its domain matches the domain in the “From” address. SPF or DKIM is enough, but both are recommended.
The tool does not find my DKIM. Is that bad?
Not necessarily: your provider may use a selector the tool does not know. Read it from a sent message (see above).
The other checkers
The tool reads public DNS records only and cannot see your messages. Built in Montreal by Yazan Rajabi.