DKIM Checker
Check whether your domain has a valid DKIM record. DKIM signs your outgoing mail so receivers can confirm it really came from you and wasn't altered.
Want the full picture - MX, SPF, DKIM, DMARC and more?
Run a full Domain CheckAbout these results
This tool reads your domain's public DKIM (TXT) records at the moment of the check. DKIM records live under a selector that is unique to each provider, so we probe common selectors and any selector you enter - a "not found" result does not always mean DKIM is missing. Results reflect current public DNS and can be affected by caching and propagation (up to 24-48 hours). Guidance is general and not a substitute for your provider's official instructions. We don't store the domains you check.What is DKIM?
DKIM (DomainKeys Identified Mail) adds a cryptographic signature to every message you send. Your provider signs with a private key and publishes the matching public key in DNS. Receivers verify the signature - proving the message really came from your domain and wasn't changed in transit.
How DKIM works
The public key lives at <selector>._domainkey.yourdomain. The selector is chosen by your provider, so a DKIM record can't be discovered without it.
Common problems and fixes
- No DKIM found: open a sent email, view headers, read the
s=value inDKIM-Signature:, and enter that selector. If you have none, enable DKIM in your provider and publish the key. - Revoked key: the record exists but
p=is empty - re-publish the public key.