← All tools

Free DNS tool

DKIM Checker

Look up a DKIM public key using its selector and domain.

These lookups show published DNS records. They do not verify inbox deliverability or prove that an email passes authentication.

Understand the lookup

What this checker is really showing

DKIM lets a receiver check a message signature against a public key in DNS. A key is looked up using both a selector and a signing domain; this tool can also follow a selector CNAME to a provider-hosted key.

Illustrative DNS record

mail._domainkey.example.com TXT "v=DKIM1; k=rsa; p=<public-key>"
DKIM specification (RFC 6376) ↗

A useful way to check

  1. 1Find the d= signing domain and s= selector in a DKIM-Signature header or your mail provider’s settings.
  2. 2Enter the domain and selector separately. The checker builds selector._domainkey.domain.
  3. 3Inspect the returned public key, then verify a real sent message with your provider or mail headers.

Read the result

Details worth noticing

Selector

A label that identifies which key signed a message. A domain can rotate keys by publishing multiple selectors.

p=

The public key material. An empty p= value indicates a revoked key, not a usable signing key.

CNAME target

Some providers delegate selector DNS to their own hostname. The lookup shows the alias and, when available, its TXT key.

Before you change a record

  • The key may be present even when your sending service is not signing messages.
  • A selector typo can look like a missing DKIM setup; verify it from the message or provider.
  • A DNS key lookup does not validate a particular message signature or DMARC alignment.

Quick answers

Where can I find my selector?

Your email provider often displays it. On a sent message, inspect the DKIM-Signature header and look for the s= value.

Why does the result show a CNAME?

Your provider may host the key at another DNS name. MailCheckr follows one selector alias and shows the public TXT key if it can resolve it.