Verify DKIM public keys and record integrity. Enter a domain with a specific selector, or let auto-detect find all active selectors.
A missing or broken DKIM signature means emails from your domain cannot be cryptographically verified — increasing the risk of spam filtering and spoofing.
Don't know your selector? We try 25+ common selectors automatically — Google, Mailgun, SendGrid, Postmark, and more — and show every active one found.
Breaks down every DKIM tag — key type, public key, testing mode, flags, service type — so you can verify each field is correct.
A DKIM record with an empty p= tag means the key has been revoked. We flag this immediately so you know all signed emails will fail verification.
The unique name that identifies which DKIM key to use. One domain can have multiple selectors — one per mail provider or key rotation.
The RSA or Ed25519 public key published in DNS. Mail servers use this to verify the cryptographic signature on your outgoing emails.
Key type. RSA 2048-bit is the standard. Ed25519 is newer, shorter, and mathematically stronger but not universally supported yet.
Testing mode flag. When set, receiving servers should not apply policy actions on DKIM failures — useful during initial setup.
Looking up DKIM record…
Use our free DKIM generator to create an RSA key pair and get your DNS record ready to publish.
Generate DKIM Keys