DKIM checker
Look up your DKIM DNS records and analyze for errors.
If your record is 'google._domainkeys.suped.com' enter 'suped.com' into the domain and 'google' into the selector. If you don't enter a selector we will scan for the most common selectors, but cannot guarantee we will find all of your DKIM records.
Check your DKIM record is valid and correct
Selector lookup
Run a live DKIM DNS lookup to verify selectors, catch syntax issues, and confirm the public key receivers use is present, readable, and strong enough for modern mail authentication. For ongoing visibility, use Suped's DMARC monitoring to track DKIM pass rates, alignment, and authentication failures over time. Use the domain health checker when you want DKIM reviewed beside SPF and DMARC for the same domain.
Get started
One DKIM checker, endless uses
Use the DKIM checker to validate a new email provider, confirm a selector after DNS propagation, audit a client's setup, or troubleshoot a failed signature. It checks the DKIM records receivers rely on now: selectors, keys, SHA-1 hashes, testing mode, and DMARC alignment.
DKIM record
google._domainkey.example.com
TXTv=DKIM1; k=rsa; p=MIGf...
Live DKIM selector lookup
Check the exact selector TXT record receivers use to verify signed mail.
google
selector1
mail
Selector discovery
Search common selectors when you do not know which DKIM name your provider uses.
Learn more
RSA
SHA-256
2048-bit
Record change guidance
Use checker results to decide whether selector DNS needs repair or rotation.
Testing mode off
t=y absent
Testing mode check
Spot t=y testing mode so it can be removed after signing is confirmed.
DKIM signature
passFrom domain aligned
Email signature context
Use the same checks with email tester results to inspect signature pass and alignment.
DNS provider
Selector managed in DNS
DNS provider context
Identify where the selector is managed so the right team can rotate or repair keys.
DKIM checker FAQs
Answers to common questions about validating DKIM records, reading selector results, and deciding what to fix next.
No. It performs a live DNS lookup and reports what is currently published.
It checks whether a DKIM TXT record exists at selector._domainkey.yourdomain.com. That record contains the public key receivers use to verify DKIM signed mail.
A selector is the label before ._domainkey in a DKIM DNS name. Email providers use selectors so one domain can publish multiple DKIM keys for different senders or rotations.
Each DKIM selector should return exactly one TXT record. Multiple records for the same selector can make DKIM verification fail because receivers do not know which public key to use.
A valid DKIM record contains a usable p= public key and valid tag-value syntax. It may include v=DKIM1, k=, h=, and t= tags, separated by semicolons.
RSA is the most widely supported DKIM key algorithm. Ed25519 can be secure, but support is still less consistent, so RSA remains the safest compatibility choice.
SHA-256 is the recommended DKIM hash algorithm. SHA-1 has known weaknesses and should be replaced by regenerating or reconfiguring DKIM keys with your provider.
For RSA DKIM keys, 2048-bit keys are the recommended minimum. 1024-bit keys are weaker and may be treated as insufficient by security-sensitive receivers.
The t=y tag marks a DKIM record as being in testing mode. Receivers may treat failures more leniently, so it should be removed after DKIM signing is confirmed.
DKIM2 is work on improving how signed email can be authenticated in the future. It is not the same thing as the DKIM TXT record you are usually asked to publish when setting up a sending platform. Read DKIM2 explained.
No, not from a blog post or draft alone. Change DKIM records when your sending provider gives you a supported setup path. Until then, keep validating the selector record your sender actually uses today. See whether to change DKIM records for DKIM2.
It becomes actionable when a sender or mailbox provider you rely on documents support and gives exact setup steps. Until then, the useful work is still normal DKIM: strong keys, clean selectors, valid DNS, and DMARC alignment. Learn when DKIM2 needs setup.
The standalone DKIM checker validates DNS records. To see whether a real message had a passing DKIM signature and whether it aligned with the From domain, use the email tester.
DMARC can pass when DKIM passes and the DKIM signing domain aligns with the From domain. For ongoing visibility into DKIM pass rates and alignment, use DMARC monitoring.

How MONEYME proactively strengthens domain security and unlocks higher email engagement with Suped
See how MONEYME uses Suped
How cybersecurity specialist Jam Cyber delivers scalable DMARC protection with Suped
See how Jam Cyber uses Suped

How Vision Australia maintains full DMARC enforcement across a large domain portfolio with Suped
See how Vision Australia uses Suped

How The POP Team turns domain checks and DMARC visibility into client ready delivery work
See how The POP Team uses Suped

How DigiBean simplified DMARC monitoring and improved email security for their MSP clients
See how DigiBean uses Suped

How Alliance Group moved from reactive guesswork to proactive email management with Suped
See how Alliance Group uses Suped
Start monitoring your DMARC reports today

What you'll get with Suped
Real-time DMARC report monitoring and analysis
Automated alerts for authentication failures
Clear recommendations to improve email deliverability
Protection against phishing and domain spoofing

