Find your DKIM key without knowing the selector.
We try 51 common selectors, read the key length and tell you if the key is missing, revoked or too short. Type your selector if you use a custom one.
Works with a domain or a full email address. Leave the selector empty and we try the common ones; your selector is the s= value in the DKIM-Signature header of an email you sent.
3 of 5 checks pass. Fix SPF first: until SPF passes, this domain falls short of the rules Gmail, Yahoo and Outlook set for bulk senders.
Found after trying 51 selectors. A receiving server uses this key to confirm that a message was signed by trynorthpeak.example and was not changed on the way.
google._domainkey.trynorthpeak.example v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzKOft5vv4mpU+bydtDHpqr/LqGEOqrochaCIpas8jTYkTibVj9ggftl4plPyRGihx0mb+Ny7mwpDLNZYiA4Lkofm+m5mSVul9IdnRBUvhrVvHwVT7S3zuy6CpyNOtp0XoKM12269bkW9uQ0gVQ6F2gs76dq/b3jY4hbAPAupkxfFw3jWnoIHMdTepTsEmTVhiR/1AzrYzrbCq471oFDX7v1QKNdE2Pl9YEANGzOM4GYSsn2S4cvJXsjERBr1RnnEBxHEmtThHCRow66FXx7PkUVPeOBqCGgW3S6mlfJ65jSeL3Q+T4+cPYto9mzkEGncaL8nLptCDH2NF2/nd1++ewIDAQAB
| Selector | Key | Usually set by |
|---|---|---|
| google._domainkey | 2048-bit RSA | Google Workspace |
We can set up your next sending domains with all five checks already passing.
We register the domains, create Google Workspace mailboxes with SPF, DKIM and DMARC in place, and connect them to Emailchaser with warm-up switched on. $6 a mailbox a month, plus $3 setup per mailbox and the domain ($16.59 a year for a .com). Ready in 24 to 48 hours.
The check runs on our server against live DNS and 16 public blocklists (3 for domains, 13 for mail server IPs). A list that does not answer is never counted as clean. Nothing you type is stored.
A DKIM key lives under a name that only your email provider chose.
DKIM proves two things about a message: that your domain signed it, and that nobody changed it on the way. The sending server signs each message with a private key. The matching public key sits in your DNS at selector._domainkey.yourdomain.com, and the receiving server looks it up to check the signature.
The catch is the selector. Nothing in DNS says which one a domain uses, so a checker has to guess, and most checkers make you type it. Ours tries the 51 names providers use by default, the same list the Emailchaser app uses when it checks a sending domain's DNS, and reports every key it finds. The old check on this site tried 8.
If your provider picked a name nobody could guess (some self-hosted servers use a random string), type it next to the domain. You will find it in the s= value of the DKIM-Signature header of any email you sent: open the message, show the original or the headers, and look for s=.
These are the 51 selectors we try, and who uses each one by default.
| Provider | Selectors |
|---|---|
| Google Workspace | |
| Microsoft 365 | selector1, selector2 |
| Shared by many hosts and control panels | default, dkim, mail, smtp, mx |
| Mailchimp and Mailgun | k1 |
| Mailchimp | k2, k3 |
| SendGrid | s1, s2 |
| Mandrill | mandrill |
| Mailjet | mailjet |
| Postmark | pm |
| Resend | resend |
| Zoho Mail | zmail, zoho |
| Fastmail | fm1, fm2, fm3 |
| Proton Mail | protonmail, protonmail2, protonmail3 |
| iCloud Mail | sig1 |
| IONOS | s1-ionos, s2-ionos |
| Hostinger | hostingermail-a, hostingermail-b, hostingermail-c |
| Titan | titan1 |
| Migadu | key1, key2, key3 |
| Gandi | gm1, gm2, gm3 |
| mailbox.org | mbo0001, mbo0002 |
| Purelymail | purelymail1, purelymail2 |
| MXroute | x |
| Brevo | brevo1, brevo2 |
| MailerLite | litesrv, ml |
| Klaviyo | kl, kl2 |
| Constant Contact | ctct1, ctct2 |
The same list as the selector probe in the Emailchaser app's DNS checks, in the same order. A provider's own default is tried first when its MX records point at it.
Gmail and Yahoo accept 1024-bit keys, and Google recommends 2048.
Google's sender guidelines say that sending to personal Gmail accounts requires a DKIM key of 1024 bits or longer, and recommend 2048 bits. Yahoo asks for a minimum of 1024 bits. Our check reads the length from the key itself: 2048 bits or more is a pass, 1024 is a warning that still works, and anything shorter fails, because Gmail ignores it.
| What we find | Result | What it means |
|---|---|---|
| A 2048-bit or longer RSA key, or an Ed25519 key | Pass | Receivers can verify your signatures. |
| A 1024-bit RSA key | Warning | It works today. Generate a 2048-bit key next time you rotate. |
| A key shorter than 1024 bits | Fail | Gmail ignores it, so your mail counts as unsigned. |
| v=DKIM1; p= with nothing after p= | Warning | The key was switched off on purpose. Mail signed with it fails. |
| A record that does not decode | Fail | Usually a key cut off while pasting it into DNS. |
| No key under any of the 51 names | Warning | DKIM is off, or it uses a custom selector. |
Google's email sender guidelines and Yahoo Sender Hub best practices, read 6 October 2026.
Google Workspace and Microsoft 365 only sign with your domain after you switch DKIM on.
Both providers sign outgoing mail with a key of their own until you set up yours, so the mail is signed, but not as your domain, and it does not count for DMARC. This is the most common DKIM problem on new cold email domains.
Google Workspace
- In the Google Admin console, open Apps, Google Workspace, Gmail, Authenticate email.
- Pick the domain and generate a new record with a 2048-bit key. The selector is google unless you change it.
- Publish the TXT record it shows at
google._domainkeyin your DNS. - Wait for DNS, then press Start authentication. Run the check above to see the key.
Microsoft 365
- In Microsoft Defender, open Email and collaboration, Policies and rules, Threat policies, Email authentication settings, DKIM.
- Pick the domain. It shows two CNAME records, for
selector1._domainkeyandselector2._domainkey. - Publish both CNAME records, then switch signing on for the domain.
- Run the check above: we follow the CNAME and read the key behind it.
A DKIM check fails for one of three reasons, and only one is a missing key.
- The key is not where the signature says. The receiver looks up the selector named in the message's
s=tag. If DNS has no key there, or a different key, the signature cannot be checked. This is the case the report above can see. - The message changed on the way. A mailing list that adds a footer, or a gateway that rewrites links, changes the signed body, and the signature no longer matches. DNS looks perfect; the failure only shows in the headers of the message that arrived, which the email header analyzer reads.
- The wrong domain signed it. The signature verifies, but its
d=domain is the sending service's, not yours. DKIM passes and DMARC still fails, because DMARC needs the signing domain to match your From address.
A DKIM record is a short list of tags, and only p= has to be there.
| Tag | Example | What it means |
|---|---|---|
| v | v=DKIM1 | Marks the record as DKIM. Optional, but if present it must come first. |
| k | k=rsa | The key type: rsa (the default) or ed25519. |
| p | p=MIIBIjANBg... | The public key itself, in base64. Empty means the key was revoked. |
| t | t=y | Testing mode: receivers are asked not to treat a failure differently from no signature. |
| h | h=sha256 | The hash algorithms the key may be used with. Rarely set. |
| s | s=email | The services the key is for. Rarely set; the default is all. |
The tags are defined in RFC 6376, and ed25519 keys in RFC 8463.
Rotate a DKIM key by publishing the new one before you remove the old one.
A key can stay in use for years, but changing it now and then limits the damage if the private key ever leaks. The safe way is to publish the new key under a new selector, switch signing to it, and leave the old key in DNS for a few days so mail already on its way still verifies. Then remove the old record, or empty its p= value to revoke it.
If you need a key pair for your own server, the DKIM record generator makes one in your browser. DKIM works together with SPF and DMARC: check the others on the SPF checker and the DMARC checker, or all five at once on the domain health check.
Common questions about DKIM
What is a DKIM selector?
The name a DKIM key is published under: <selector>._domainkey.<your domain>. It lets one domain keep several keys, one per sending service. Your selector is the s= value in the DKIM-Signature header of any email you send.
Why does the checker say no DKIM key was found?
We try the 51 names providers use by default. If none of them holds a key, DKIM is either off or published under a custom name. Type your selector next to the domain and we read that key directly.
Is a 1024-bit DKIM key still OK?
It works: Gmail and Yahoo both accept keys of 1024 bits or longer. Google recommends 2048 bits, so we mark 1024-bit keys as a warning, not a failure.
What does an empty p= value mean?
The key was switched off on purpose. A record like v=DKIM1; p= tells receivers that mail signed with that selector should fail DKIM. If you still sign with it, publish the key again from your provider's settings.
Can I have more than one DKIM key?
Yes, one per selector. Most domains have one for their mailbox provider and one for each service that sends as them, such as a newsletter tool or a help desk. Our check lists every key it finds.
What does d= mean in a DKIM signature?
The domain that signed the message. DMARC only counts a DKIM pass when d= matches the domain in your From address, or its parent. A provider that signs with its own domain gives you a DKIM pass that does nothing for DMARC.
Does a DKIM record work as a CNAME?
Yes. Microsoft 365 and many sending services ask for a CNAME at selector._domainkey that points at a key they host and rotate. Receivers follow the CNAME, and so does our check.
Do I need DKIM if SPF already passes?
Yes. Gmail, Yahoo and Outlook require both from bulk senders, and DKIM is the one that survives forwarding, so DMARC leans on it most.
More free tools for your sending setup
Send cold email from domains that pass all five checks.
Every plan includes warm-up, follow-ups and unlimited email accounts, from $47 a month.
Start my free trial7-day free trial, $0 today