Free DKIM Tester & Record Checker
Enter a domain to run DKIM checks across detected selectors, inspect the public keys found, and flag missing or invalid records before a real-message test.
What is a DKIM record?
A DKIM record publishes the public key used to verify a message signature. Each key lives at a selector-specific DNS name. This tester inspects records on the selectors it detects, while a real-message test is still required to prove that the production path signed the message and that the signature passed at the receiver.
How to read your DKIM result
| Result | What it means | What to do |
|---|---|---|
| Detected public key | The scan found a DKIM record with a readable public key on a detected selector. | Send a new production message and confirm that the receiver records dkim=pass for the same d= domain and s= selector. |
| No record found | The domain scan returned no usable record on the selectors it detected. | Confirm d= and s= from a real message or the provider; a custom selector may need a separate exact lookup. |
| Malformed or incomplete | The TXT value cannot be interpreted as the public key the sender expects. | Compare it byte-for-byte with the provider value, remove accidental quotes or line breaks, publish the correction, and wait for TTL. |
| Empty p= value | The selector is revoked and no longer supplies a public key for verification. | Stop signing with that key or activate the intended replacement selector before retesting. |
| DNS valid, message fails | The record exists, but the receiver could not verify the signature on the tested message. | Check the exact message path, d= and s= values, body-hash result, post-signing modifications, and DMARC alignment. |
How to run useful DKIM checks
Start with a message sent through the production path you need to verify. In its DKIM-Signature header, note the d= signing domain and s= selector. Enter the signing domain, then compare the selectors returned by the scan with the message. If the exact selector is absent, this tester has not checked that record.
If the result conflicts with a provider dashboard, query the authoritative nameserver and compare the exact owner name and value. Common causes are the wrong selector, the root domain being used instead of the signing domain, a provider CNAME pointing to an inactive target, or a record that has not reached the authoritative zone.
What this checker can prove
This checker shows what public DNS returns for the selectors it detects and whether those records contain usable keys. It cannot prove that it found every selector, that all sending systems sign, that a receiver accepted a particular signature, or that DKIM aligns for DMARC. Those answers require the original headers of a newly delivered message.
Verify DKIM on a real email
Send the same message type through every important production path, preserve the receiver's original source, and read a trusted Authentication-Results header. A dkim=none result normally means that path did not sign. A dkim=fail result requires the recorded reason, selector lookup, and any post-signing content changes. A pass still needs alignment: compare the DKIM d= domain with the visible From domain using the DMARC checker and the message result together.
Related DKIM checks and repairs
Email authentication knowledge base
Can this DKIM tester check every selector?
No. This domain scan reports the selectors it detects, but it may miss a custom selector. Compare the result with the s= selector and d= signing domain in a real message's DKIM-Signature header or the current sending provider configuration.
Does a published DKIM record prove email is being signed?
No. A public key proves that DNS serves a record for that selector. It does not prove that every production sending path adds a signature, uses the same selector, survives message modification, or passes at the receiver. Verify a newly delivered message separately.
What does an empty DKIM p= value mean?
An empty p= value revokes the public key for that selector. A sender still signing with the corresponding private key will fail verification. Confirm that the selector is intentionally retired before removing it or activating a replacement.
Why does DKIM pass but DMARC fail?
DMARC requires the passing DKIM d= domain to align with the visible From domain. DKIM can validate a provider-owned signing domain while DMARC still fails alignment. Compare the exact domains and then configure a custom aligned signature when the provider supports it.
What should I do when a message reports dkim=none?
Check whether the message has a DKIM-Signature header. If it does not, enable DKIM on that exact production path. If it does, confirm you are reading a trusted receiver-added Authentication-Results header and inspect whether the receiver recorded a different authentication result.
Can a DKIM checker guarantee inbox placement?
No. DKIM is one authentication signal. Receivers also evaluate DMARC alignment, SPF, sender and IP reputation, recipient engagement, content, and private policy. A valid record and a passing signature are necessary evidence, not a placement guarantee.
The tags you'll find inside a DKIM record and what each one means.
- v
- The version tag specifies DKIM’s version, consistently required to be 1.
- p
- The public key tag, a character string created in DKIM setup, must not be left empty to remain valid.
- t
- This tag enumerates flags as a colon-separated sequence, with “y” and “s” as defined flags; any undefined flags should be disregarded.
- s
- This tag details service types relevant to the record. Absent or unrecognized service types must be overlooked by receiving servers.
- h
- This tag specifies permitted hash algorithms, defaulting to allow all. Receivers should ignore unknown algorithms, with the sender determining the list’s entries.
- n
- This tag serves as an optional note field for administrators, recommended for use only when needed.