SmartReach.io LogoSmartReach.io

Free tool · no signup

Free DKIM checker

Look up the DKIM record on any domain and find out whether it actually works. This tool reads your live DNS, validates the key, and tells you in plain language what is wrong.

Ungated · no email required · unlimited checks

In short

  • This is a free, ungated DKIM checker. It reads the TXT record at <selector>._domainkey.<domain> over DNS and reports whether a valid public key is published there.
  • DKIM (DomainKeys Identified Mail) adds a cryptographic signature to outgoing email. Receivers verify that signature against a public key published in the sending domain's DNS, which proves the message came from that domain and was not altered in transit.
  • The checker validates the record against RFC 6376: it confirms the v=DKIM1 version tag, parses the public key, reports RSA key length, and flags a revoked key (an empty p= value), testing mode (t=y), a hash list that excludes sha256, and CNAME delegation to a provider.
  • DNS provides no way to enumerate the selectors a domain uses, so no DKIM checker can list every record on a domain. Supplying the selector gives a definitive answer; leaving it blank probes the selectors used by common providers and reports only what it finds.
  • DKIM works alongside SPF and DMARC and does not replace either. Gmail and Yahoo require bulk senders to have all three configured.

Leave the selector blank and we will probe the selectors used by common providers. Know yours? Enter it for a definitive answer. It is the s= value in the DKIM-Signature header of any email you have sent.

4.6 on G25,000+ sales teams and agenciesGDPR · CAN-SPAM
Record existsKey parsesRSA key lengthRevoked keysTesting modeHash algorithmsCNAME delegationWildcard recordsDNSSEC
googleselector_domainkeyalways thisexample.comyour domain

The selectorChosen by your sending platform. One domain can publish several, one per platform.

The fixed labelNever changes. Every DKIM key on every domain sits under this label.

Your domainThe domain in the From address, matching the d= value in the signature.

The other two records

DKIM is one of three checks

Receivers run SPF, DKIM and DMARC together. A perfect DKIM record still fails you if the other two are missing or misconfigured.

Which servers may send as you

SPF Checker

SPF lists the servers allowed to send mail for your domain. Check that yours is published, resolves, and stays under the ten-lookup limit that silently breaks it.

What it looks like

v=spf1 include:_spf.google.com ~all

What happens when a check fails

DMARC Checker

Coming soon

DMARC tells receivers whether to quarantine or reject mail that fails SPF and DKIM, and where to send the reports. Check your policy, alignment and reporting address.

What it looks like

v=DMARC1; p=reject; pct=100

The basics

What a DKIM record is

DKIM, or DomainKeys Identified Mail, lets a receiving mail server confirm that a message genuinely came from your domain and was not tampered with on the way. It works in three moves.

Your platform

Signs the message

Every outgoing email is signed with a private key that only your sending platform holds.

Your DNS

Publishes the public key

The matching public half sits in a TXT record on your domain, where anyone can read it.

The receiver

Verifies the signature

Gmail or Outlook reads the selector from the header, fetches your key, and checks the signature holds.

If the check passes, the message carries a verified claim of origin. If it fails, or no key is published, the message loses that signal. Gmail and Yahoo both require bulk senders to authenticate with SPF, DKIM and DMARC, so for cold email a broken DKIM record is not a minor detail.

Thirty seconds

How the DKIM checker works

Enter your domain

The domain in your From address, for example example.com. A full URL or an email address works too.

Add your selector

Optional. It is the s= value in the DKIM-Signature header of any email you have sent. Leave it blank to probe the selectors common providers use.

Run the check

The tool queries live DNS for the record at <selector>._domainkey and reads the key it finds. No signup, no email, no limit.

Read the verdict

You get key type and length, plus plain-language flags for revoked keys, testing mode, weak hashes, CNAME delegation and wildcard records.

If an email you have sent carries no DKIM-Signature header at all, your platform is not signing yet. Turn DKIM on there first, because no DNS record will help until it does.

No DKIM checker can find every record on a domain, and any tool that claims otherwise is overstating what DNS can do.

DNS answers questions about names you ask for. It has no query that returns a list of the selectors under a domain. A tool can look up a selector you supply, or probe selectors that known providers use, and that is all.

Leaving the selector blank above probes the fixed selectors published by common providers. Providers that mint a per-account selector, such as HubSpot, Amazon SES and SparkPost, cannot be guessed. An empty result means nothing was found at the names we tried, never that your domain has no DKIM.

Read your record

What each tag means

TagWhat it does
v=Version. Must read DKIM1, and should be the first tag in the record.
k=Key type. Almost always rsa; ed25519 is the modern alternative.
p=The public key itself, base64 encoded. Empty means the key is revoked.
h=Hash algorithms the key may be used with. Should allow sha256.
t=Flags. t=y means testing mode; t=s stops the key covering subdomains.
s=Service type. Defaults to * (any); email restricts the key to mail.
n=A free-text note for administrators. Ignored by verifiers.

What usually breaks

The three faults worth knowing

p=

An empty public key

The key is revoked, which is worse than having no record. It is an explicit instruction to receivers not to trust anything signed with that selector.

1024-bit

An undersized RSA key

It still verifies, so mail passes today. But 2048-bit is the current recommendation and what providers now issue by default. Regenerate and republish.

t=y

Testing mode left on

Receivers are told to behave as though you were not signing at all. Useful while you confirm setup, worthless once you have, so take it off.

Once DKIM passes

Or skip the DNS editing entirely

Authentication is the entry requirement, not the finish line. SmartReach hands you sending domains and mailboxes with all three records already in place, then keeps the reputation behind them healthy.

  • Sending domains and mailboxes bought and authenticated in minutes, no IT ticket
  • SPF, DKIM and DMARC configured for you, so there is no record to hand-edit
  • Warmup, inbox rotation and ESP matching across unlimited sending accounts
  • Every address verified free before a campaign sends, so bounces never touch your domain
See the deliverability suite →
Photo of Matt McQuinThis software is focused on the end receiver as much as the user.Matt McQuin · Co-founder, Coldlytics

FREQUENTLY ASKED QUESTIONS

DKIM questions, answered

A DKIM record is a TXT record in your domain’s DNS that publishes the public half of the key your email platform signs with. It lives at <selector>._domainkey.<yourdomain>, for example google._domainkey.example.com. Receiving mail servers fetch it to verify the signature on each message, which proves the mail really came from your domain and was not altered in transit.

Stop fixing deliverability one DNS record at a time.

SmartReach buys and authenticates your sending domains and mailboxes with SPF, DKIM and DMARC already in place, then warms them, rotates them, and verifies every address before you send.

14-day free trial No credit card All features included Unlimited sending inboxes