Menu

DKIM checker: find and test your DKIM key for cold email

Type a domain, and your DKIM selector if you know it, and see whether a DKIM public key is published, whether it is live or revoked, and whether it is the 2048-bit length current guidance recommends. Free, no sign-up, nothing stored.

What does this DKIM checker test for cold email?

It looks up the DKIM public key at selector._domainkey.yourdomain.com, first at the selector you enter, then at the ones the common mailbox hosts use (google for Google Workspace, selector1 and selector2 for Microsoft 365, and others). For the key it finds, it checks that the key is live rather than revoked with an empty p=, and estimates its length.

How do I find my DKIM selector?

Open an email you sent from the domain, view the original message or its headers, and find the DKIM-Signature line. The value after s= is the selector, and the value after d= is the domain that signed it. If d= is not your domain, your sending tool is signing with its own, and DMARC will not count that signature for you. Our guide to what DKIM is shows the header in full.

Is a 1024-bit DKIM key still OK for cold email?

Most receivers still accept 1024-bit keys, so mail will not fail because of one. Current guidance recommends 2048 bits, and most hosts now issue them by default. If the checker flags a short key, rotate to a 2048-bit key in your mailbox host when convenient, publish it at a new selector, and remove the old one after a few days.

Why can a DKIM checker not list every key on a domain?

DNS has no way to list the names under _domainkey. A checker can only ask about selectors it can guess or that you give it, so "no key found" at the common selectors does not prove DKIM is off. Check all four records at once with the full domain checker, or turn a key your host gave you into a record with the DKIM record generator.