Email security
DKIM checker
Look up the DKIM public keys a domain publishes, at the selector you enter and at 13 selectors common mail services use, and read each key's type, size and status. Receivers use these keys to verify the signatures your mail services add to outgoing mail.
What this checks
- TXT records at
<selector>._domainkey.<domain>for up to three selectors you enter, separated by commas or spaces, then for 13 common ones:google,selector1,selector2,default,k1,s1,s2,dkim,mail,smtp,mandrill,mxvaultandzoho. - Each key's type (
k=, RSA unless the record says otherwise) and its size in bits, read from the public key inp=. - Whether a key is revoked: an empty
p=tag means the key has been withdrawn (RFC 6376). - Whether a key is in testing mode (
t=y). - Without a selector, the check runs only for a domain that sends or receives mail: one with MX records, or an SPF record that authorises senders.
What the result means
DKIM (RFC 6376) lets a mail service sign each message it sends with a private key. The matching public key is published in DNS under a selector, a name the service chooses, and a receiver uses it to check that the message was not altered and was signed for the domain in the signature's d= tag.
A pass means at least one key was found. Selectors cannot be listed from DNS, so when no key is found at the selectors tried, the result is that DKIM could not be confirmed, not that it is missing: your mail service may sign with a name the check did not try. The selector is the s= tag in a message's DKIM-Signature header, and your mail service's DKIM settings show it too; enter it to check that key directly.
For each key found, look at the size and status. RFC 8301 requires RSA keys of at least 1024 bits and recommends 2048, and the result notes a shorter RSA key. An empty p= is a key deliberately withdrawn, usually after rotation, so mail should be signed under another selector. A key in testing mode (t=y) asks receivers not to treat a failed signature differently from unsigned mail; remove the flag once signing works.
How to fix common issues
DKIM could not be confirmed
Confirm in your mail service (Google Workspace, Microsoft 365 and others) that DKIM signing is turned on for the domain.
Cyber Essentials and ISO 27001
Neither Cyber Essentials nor ISO 27001 names DKIM. Signing outgoing mail is technical evidence for broader ISO/IEC 27001:2022 Annex A controls: 5.14, information transfer, for protecting information sent by email, and 8.24, use of cryptography, for the keys that do the signing.
The organisation still has to establish who manages the signing keys, which mail services may sign for the domain, how often keys are rotated and when old selectors are removed. A published key shows what is in DNS, not the rules behind it.
Scope and limitations
- Selectors cannot be listed from outside, so the check can only try names: those you enter and 13 common ones. A domain with no key at any of them may still sign its mail.
- It reads keys from public DNS and does not see a signed message, so it cannot tell whether your mail service actually signs with a key, or whether the signing domain aligns with your From address for DMARC.
- A key at a common selector may belong to a service you no longer use; the check cannot tell a live key from a forgotten one.
- Key size, revocation and testing mode are shown for you to assess but are not raised as findings. The check does not send or receive email.
Related guides
Questions
- How do I find my DKIM selector?
- Open a message your domain sent, view its headers and find the DKIM-Signature header: the s= tag is the selector and d= is the signing domain. Your mail service's DKIM settings show the selector as well.
- Why does the checker say DKIM could not be confirmed?
- DNS has no way to list a domain's selectors, so the check tries the ones you enter and 13 common ones. If your mail service uses another name, no key is found even though DKIM may be working. Enter your selector to check it.
- What size should a DKIM key be?
- For RSA, 2048 bits. RFC 8301 requires signers to use RSA keys of at least 1024 bits and recommends at least 2048.
- Do I need DKIM if I already have SPF?
- Yes. SPF fails when mail is forwarded, because the forwarding server is not in your record, while a DKIM signature usually survives forwarding. DMARC passes when either SPF or DKIM passes and aligns with the From domain, so DKIM keeps forwarded mail passing.
Related security tools
- DMARC checker - Look up a domain's DMARC record, read its policy and reporting, and see what to change.
- SPF checker - Check a domain's SPF record, its all mechanism and how many of the 10 DNS lookups it uses.
- Email security checker - Check MX, SPF, DMARC and DKIM together, and the protection of a domain that sends no mail.
- DNS checker - Look up a domain's A, AAAA, CNAME, MX, TXT, NS, SOA, CAA and DS records through public resolvers.

