Suped

DKIM checker

Look up your DKIM DNS records and analyze for errors.
If your record is 'google._domainkeys.suped.com' enter 'suped.com' into the domain and 'google' into the selector. If you don't enter a selector we will scan for the most common selectors, but cannot guarantee we will find all of your DKIM records.

Check your DKIM record is valid and correct

Selector lookup
Run a live DKIM DNS lookup to verify selectors, catch syntax issues, and confirm the public key receivers use is present, readable, and strong enough for modern mail authentication. For ongoing visibility, use Suped's DMARC monitoring to track DKIM pass rates, alignment, and authentication failures over time. Use the domain health checker when you want DKIM reviewed beside SPF and DMARC for the same domain.
Get started
outcome left image

One DKIM checker, endless uses

Use the DKIM checker to validate a new email provider, confirm a selector after DNS propagation, audit a client's setup, or troubleshoot a failed signature. It checks the DKIM records receivers rely on now: selectors, keys, SHA-1 hashes, testing mode, and DMARC alignment.
DKIM record
google._domainkey.example.com
TXTv=DKIM1; k=rsa; p=MIGf...
Live DKIM selector lookup
Check the exact selector TXT record receivers use to verify signed mail.
google
selector1
mail
Selector discovery
Search common selectors when you do not know which DKIM name your provider uses.
Learn more
RSA
SHA-256
2048-bit
Record change guidance
Use checker results to decide whether selector DNS needs repair or rotation.
Testing mode off
t=y absent
Testing mode check
Spot t=y testing mode so it can be removed after signing is confirmed.
DKIM signature
pass
From domain aligned
Email signature context
Use the same checks with email tester results to inspect signature pass and alignment.
DNS provider
Selector managed in DNS
DNS provider context
Identify where the selector is managed so the right team can rotate or repair keys.

DKIM checker FAQs

Answers to common questions about validating DKIM records, reading selector results, and deciding what to fix next.
No. It performs a live DNS lookup and reports what is currently published.
It checks whether a DKIM TXT record exists at selector._domainkey.yourdomain.com. That record contains the public key receivers use to verify DKIM signed mail.
A selector is the label before ._domainkey in a DKIM DNS name. Email providers use selectors so one domain can publish multiple DKIM keys for different senders or rotations.
Each DKIM selector should return exactly one TXT record. Multiple records for the same selector can make DKIM verification fail because receivers do not know which public key to use.
A valid DKIM record contains a usable p= public key and valid tag-value syntax. It may include v=DKIM1, k=, h=, and t= tags, separated by semicolons.
RSA is the most widely supported DKIM key algorithm. Ed25519 can be secure, but support is still less consistent, so RSA remains the safest compatibility choice.
SHA-256 is the recommended DKIM hash algorithm. SHA-1 has known weaknesses and should be replaced by regenerating or reconfiguring DKIM keys with your provider.
For RSA DKIM keys, 2048-bit keys are the recommended minimum. 1024-bit keys are weaker and may be treated as insufficient by security-sensitive receivers.
The t=y tag marks a DKIM record as being in testing mode. Receivers may treat failures more leniently, so it should be removed after DKIM signing is confirmed.
DKIM2 is work on improving how signed email can be authenticated in the future. It is not the same thing as the DKIM TXT record you are usually asked to publish when setting up a sending platform. Read DKIM2 explained.
No, not from a blog post or draft alone. Change DKIM records when your sending provider gives you a supported setup path. Until then, keep validating the selector record your sender actually uses today. See whether to change DKIM records for DKIM2.
It becomes actionable when a sender or mailbox provider you rely on documents support and gives exact setup steps. Until then, the useful work is still normal DKIM: strong keys, clean selectors, valid DNS, and DMARC alignment. Learn when DKIM2 needs setup.
The standalone DKIM checker validates DNS records. To see whether a real message had a passing DKIM signature and whether it aligned with the From domain, use the email tester.
DMARC can pass when DKIM passes and the DKIM signing domain aligns with the From domain. For ongoing visibility into DKIM pass rates and alignment, use DMARC monitoring.

Here's why customers love Suped for DMARC monitoring

MONEYME cover

How MONEYME proactively strengthens domain security and unlocks higher email engagement with Suped

See how MONEYME uses Suped
Jam Cyber cover

How cybersecurity specialist Jam Cyber delivers scalable DMARC protection with Suped

See how Jam Cyber uses Suped
Vision Australia cover

How Vision Australia maintains full DMARC enforcement across a large domain portfolio with Suped

See how Vision Australia uses Suped
The POP Team cover

How The POP Team turns domain checks and DMARC visibility into client ready delivery work

See how The POP Team uses Suped
DigiBean cover

How DigiBean simplified DMARC monitoring and improved email security for their MSP clients

See how DigiBean uses Suped
Alliance Group cover

How Alliance Group moved from reactive guesswork to proactive email management with Suped

See how Alliance Group uses Suped
G2 LeaderG2 Users Most Likely To RecommendG2 Easiest To Do Business WithG2 High PerformerG2 Best Estimated ROI
DMARC monitoring

Start monitoring your DMARC reports today

Suped DMARC platform dashboard
What you'll get with Suped
Real-time DMARC report monitoring and analysis
Automated alerts for authentication failures
Clear recommendations to improve email deliverability
Protection against phishing and domain spoofing