DKIM check: is your published key valid?
Enter a domain and a selector and see the published DKIM key: whether the record is valid, how long the key is, and whether receivers can use it to verify signatures. If you do not know the selector, leave it empty and we try the most common ones.
What the DKIM check covers
- Key record
- Whether there is exactly one key under selector._domainkey, and whether it is published directly or through an alias (CNAME) to the mail provider.
- Syntax
- Whether every tag is valid, the public key is present, and no quotation marks or other stray characters ended up in the record.
- Key length
- How many bits the RSA key has. Receivers refuse keys shorter than 1024 bits and consider 1024-bit keys weak today; the recommended size is 2048 bits.
- Cut-off keys
- Long keys are often truncated when they are pasted in; the record is then there, but every signature fails.
- Flags
- Whether the key is in test mode (t=y), revoked (empty p=), or limited to the domain without its subdomains.
- Selector search
- Without a selector, more than thirty names commonly used by mail services are tried.
Frequently asked questions
What is a DKIM selector, and where do I find it?
The selector is the name of the key: a domain can have several keys, one for each service that sends its mail. Your mail service gives it to you during setup. You can also read it from a message that was already sent: open the message source and look for "s=" in the DKIM-Signature header.
How long should a DKIM key be?
Use a 2048-bit RSA key. A 1024-bit key still works but is considered weak, and receivers ignore anything shorter. A 2048-bit key is longer than 255 characters, so in the TXT record it has to be split into several pieces; most DNS editors do that for you.
The record is there, yet DKIM fails. Why?
The most common cause is a key that was cut off when pasted in, or joined with quotation marks; the check reports both. Other causes: mail is signed with a different selector from the one you published, or the message was changed on the way (a mailing list adding a footer, for example).
Is DKIM enough without SPF?
For DMARC it is enough if one of the two passes, but set up both. DKIM survives forwarding and SPF does not; SPF in turn still protects when a service does not sign.