Skip to content

Email security

DKIM checker

Look up the DKIM public keys a domain publishes, at the selector you enter and at 13 selectors common mail services use, and read each key's type, size and status. Receivers use these keys to verify the signatures your mail services add to outgoing mail.

Checked from Ironfang Security's scanner address with the same low-impact limits as a scan. Nothing you enter is kept.

What this checks

What the result means

DKIM (RFC 6376) lets a mail service sign each message it sends with a private key. The matching public key is published in DNS under a selector, a name the service chooses, and a receiver uses it to check that the message was not altered and was signed for the domain in the signature's d= tag.

A pass means at least one key was found. Selectors cannot be listed from DNS, so when no key is found at the selectors tried, the result is that DKIM could not be confirmed, not that it is missing: your mail service may sign with a name the check did not try. The selector is the s= tag in a message's DKIM-Signature header, and your mail service's DKIM settings show it too; enter it to check that key directly.

For each key found, look at the size and status. RFC 8301 requires RSA keys of at least 1024 bits and recommends 2048, and the result notes a shorter RSA key. An empty p= is a key deliberately withdrawn, usually after rotation, so mail should be signed under another selector. A key in testing mode (t=y) asks receivers not to treat a failed signature differently from unsigned mail; remove the flag once signing works.

How to fix common issues

DKIM could not be confirmed

Confirm in your mail service (Google Workspace, Microsoft 365 and others) that DKIM signing is turned on for the domain.

More in the DKIM check reference

Cyber Essentials and ISO 27001

Neither Cyber Essentials nor ISO 27001 names DKIM. Signing outgoing mail is technical evidence for broader ISO/IEC 27001:2022 Annex A controls: 5.14, information transfer, for protecting information sent by email, and 8.24, use of cryptography, for the keys that do the signing.

The organisation still has to establish who manages the signing keys, which mail services may sign for the domain, how often keys are rotated and when old selectors are removed. A published key shows what is in DNS, not the rules behind it.

Scope and limitations

Related guides

Questions

How do I find my DKIM selector?
Open a message your domain sent, view its headers and find the DKIM-Signature header: the s= tag is the selector and d= is the signing domain. Your mail service's DKIM settings show the selector as well.
Why does the checker say DKIM could not be confirmed?
DNS has no way to list a domain's selectors, so the check tries the ones you enter and 13 common ones. If your mail service uses another name, no key is found even though DKIM may be working. Enter your selector to check it.
What size should a DKIM key be?
For RSA, 2048 bits. RFC 8301 requires signers to use RSA keys of at least 1024 bits and recommends at least 2048.
Do I need DKIM if I already have SPF?
Yes. SPF fails when mail is forwarded, because the forwarding server is not in your record, while a DKIM signature usually survives forwarding. DMARC passes when either SPF or DKIM passes and aligns with the From domain, so DKIM keeps forwarded mail passing.

Related security tools