Domain-only scan
No selector required — we probe 40+ common ESP selectors (Google, Microsoft, SES, SendGrid, Zoho, and more) in one click.
Free tools
Enter your domain only. We scan dozens of common DKIM selectors, parse each TXT record, explain every tag, and show key strength — no guessing which selector your provider uses.
You send mail
Your mail server or ESP signs the message with a private key and adds a DKIM-Signature header (s= selector, d= domain).
Receiver looks up DNS
The receiving server queries TXT at selector._domainkey.yourdomain.com for the public key (p= tag).
Signature verified
If the signature matches and the signing domain aligns with From, DKIM passes — supporting DMARC and inbox placement.
Enter your domain — we automatically query 40+ common selectors, parse every DKIM TXT record, and explain each tag. No manual selector lookup required.
| Tag | Name | Meaning |
|---|---|---|
| v | Version | Must be DKIM1. Anything else is ignored by receivers. |
| k | Key type | rsa (default) or ed25519 — tells verifiers how to decode the public key. |
| p | Public key | Base64-encoded public key. Empty p= revokes DKIM; truncation here breaks all verification. |
| h | Signed headers | Which headers are included in the signature (e.g. from:to:subject). Defaults if omitted. |
| s | Service type | Usually * (any). Restricts which header fields may appear unsigned. |
| t | Flags | y = testing mode; s = strict — only listed headers may be unsigned. |
| i | Identity | Optional signing identity (AUID) — often matches the From domain. |
| l | Body length | Discouraged. Limits how many body bytes are signed — can weaken integrity. |
| q | Query method | How to fetch the key — dns/txt is standard. |
| n | Notes | Human notes for admins. Not used in verification. |
Capabilities
Stop guessing selectors. One domain scan surfaces every published DKIM record with tag-by-tag explanations.
No selector required — we probe 40+ common ESP selectors (Google, Microsoft, SES, SendGrid, Zoho, and more) in one click.
Every found selector shows the raw TXT record, parsed tags, key type, bit length, and issues.
Each DKIM tag (v, k, p, h, t…) includes a plain-language explanation — learn while you troubleshoot.
Flags weak 1024-bit RSA, validates 2048-bit and Ed25519, and detects truncated public keys.
Scans selectors used by Google Workspace, Microsoft 365, Mailchimp, HubSpot, Zendesk, and other major senders.
Image captcha and per-IP rate limits keep the public checker reliable at scale.
How to use
Use the domain you send from (the d= value in DKIM-Signature or your From address domain).
One quick verification — then we query DNS across all common selectors.
Expand each selector card to see tags, key length, issues, and the full TXT record.
Copy the correct selector from results into your provider panel if anything is missing or weak.
DNS propagation can take minutes to hours — run the scan again to confirm keys are live.
DomainKeys Identified Mail (DKIM) lets receiving mail servers verify that a message was authorized by your domain and was not altered in transit. Your sending infrastructure signs each message with a private key; receivers fetch the matching public key from DNS and validate the cryptographic signature.
DKIM does not stop spoofing by itself — but when aligned with your From domain, it is a core input to DMARC pass/fail decisions and strongly influences inbox placement at Gmail, Microsoft, Yahoo, and other major providers.
A DKIM record lives at selector._domainkey.yourdomain.com as a DNS TXT record. The selector is the s= value in the DKIM-Signature header on outbound mail. Different services use different selectors — Google often uses google, Microsoft uses selector1, Amazon SES uses a custom token.
Most senders only need one active selector, but migrations, multi-ESP setups, or provider rotations can leave multiple records published. Our checker scans the selectors major providers actually use so you do not have to guess.
DMARC evaluates whether the DKIM signing domain (d=) aligns with the visible From: header domain. Relaxed alignment allows organizational domain match; strict requires an exact match.
Publish SPF and DMARC alongside DKIM. Use our SPF checker and DMARC checker on the same domain after validating DKIM records here.
This checker validates DNS publication: record syntax, public key format, key length, and common misconfigurations. It does not send email or prove your SMTP path signs with a specific selector.
If no records are found, enable DKIM in your email provider and publish the TXT record they supply. Custom selectors outside our scan list can be checked via the advanced single-selector field.
For regulatory context on commercial email in the United States, see the FTC CAN-SPAM compliance guide.
Delivery note: MailFleet helps users manage campaigns through their own sending providers. Delivery outcomes depend on sender reputation, DNS authentication, content quality, recipient engagement, list quality, provider rules, and mailbox filtering systems.
No. Enter your domain only — we scan 40+ common selectors used by Google, Microsoft, Amazon SES, SendGrid, Mailchimp, Zoho, and others. If your provider uses a rare custom selector, use the advanced single-selector check.
Get started
Configure providers, validate DKIM alignment, and run pre-send checks from your desktop.
Available on
Same desktop experience across every platform — one workflow for your entire team.