LeadHaste
← Back to Free Tools

Free tool · Deliverability DKIM Checker

Look up and validate your domain's DKIM record. Don't know your selector? We'll auto-detect the common ones, confirm your public key is published, and flag weak keys and test mode.

01The tool

Find your selector in the DKIM DNS record your email provider gave you (Google Workspace uses google, Microsoft 365 uses selector1/selector2).

02Guide

How to read your DKIM results

DKIM proves an email actually came from your domain and wasn't altered along the way. It works by signing each message with a private key, while the matching public key sits in your DNS for receivers to verify against. When DKIM is missing or broken, inbox providers trust your mail less, and your cold email pays the price.

The selector matters

DKIM records live at selector._domainkey.yourdomain.com, not on your root domain. That selector is assigned by whatever service sends your mail. If you don't know it, this tool tries the most common selectors automatically, but the surest way is to copy it straight from your email provider's authentication settings.

A published, strong public key

We confirm the record contains a non-empty public key (an empty p= value means the key has been revoked and DKIM will fail) and estimate whether it's 1024-bit or 2048-bit. We also flag t=y, which puts DKIM in test mode and tells receivers to ignore failures, fine during setup, but it should be removed once signing works.

DKIM works best alongside SPF and DMARC

DKIM verification feeds directly into DMARC, which is what actually enforces a policy and gives you reporting. Pair this check with the SPF checker and DMARC checker, or run the combined deliverability test for one score across all three.

We configure DKIM signing across every sending domain we build for clients and monitor it over time. Learn how our cold email infrastructure works, or read the full SPF, DKIM & DMARC guide.

03FAQ

Frequently asked questions

What is DKIM?

DKIM (DomainKeys Identified Mail) adds a cryptographic signature to every email you send. The receiving server uses a public key published in your DNS to verify the message genuinely came from your domain and wasn't tampered with in transit. Along with SPF and DMARC, it's one of the three authentication standards inbox providers expect.

How do I check my DKIM record?

Enter your domain above. If you know your selector, add it; if not, we'll automatically try the most common ones (google, selector1, selector2, k1, default, and more). We look up the record at selector._domainkey.yourdomain.com, confirm a public key is published, and estimate the key strength.

What is a DKIM selector?

A selector is a label that lets a domain publish multiple DKIM keys at once (for different sending services). It's part of the DNS name where the key lives: selector._domainkey.yourdomain.com. Google Workspace uses "google", Microsoft 365 uses "selector1" and "selector2", and many email platforms use "k1". You'll find yours in the DKIM setup screen of your email provider.

Why can't the tool find my DKIM record?

The most common reason is a custom selector we didn't guess. Check your email provider's DKIM/authentication settings for the exact selector name, then enter it above. The other possibility is that DKIM simply isn't set up yet, in which case your provider will have a one-time setup step that gives you a DNS record to publish.

Should I use a 1024-bit or 2048-bit DKIM key?

2048-bit is the current recommendation. It's significantly harder to crack than 1024-bit, and all major providers support it. If our checker flags your key as 1024-bit and your provider allows it, regenerate at 2048-bit. The trade-off is that a 2048-bit key may need to be split across two DNS strings, which most DNS hosts handle automatically.

Want us to build your outbound system?

Skip the DIY. We'll orchestrate your entire outbound operation, on infrastructure registered in your name from day one.

Book your free ICP review →