Skip to Main Content

Free DKIM Tester & Record Checker

Enter a domain to run DKIM checks across detected selectors, inspect the public keys found, and flag missing or invalid records before a real-message test.

What is a DKIM record?

A DKIM record publishes the public key used to verify a message signature. Each key lives at a selector-specific DNS name. This tester inspects records on the selectors it detects, while a real-message test is still required to prove that the production path signed the message and that the signature passed at the receiver.

How to read your DKIM result

ResultWhat it meansWhat to do
Detected public keyThe scan found a DKIM record with a readable public key on a detected selector.Send a new production message and confirm that the receiver records dkim=pass for the same d= domain and s= selector.
No record foundThe domain scan returned no usable record on the selectors it detected.Confirm d= and s= from a real message or the provider; a custom selector may need a separate exact lookup.
Malformed or incompleteThe TXT value cannot be interpreted as the public key the sender expects.Compare it byte-for-byte with the provider value, remove accidental quotes or line breaks, publish the correction, and wait for TTL.
Empty p= valueThe selector is revoked and no longer supplies a public key for verification.Stop signing with that key or activate the intended replacement selector before retesting.
DNS valid, message failsThe record exists, but the receiver could not verify the signature on the tested message.Check the exact message path, d= and s= values, body-hash result, post-signing modifications, and DMARC alignment.

How to run useful DKIM checks

Start with a message sent through the production path you need to verify. In its DKIM-Signature header, note the d= signing domain and s= selector. Enter the signing domain, then compare the selectors returned by the scan with the message. If the exact selector is absent, this tester has not checked that record.

If the result conflicts with a provider dashboard, query the authoritative nameserver and compare the exact owner name and value. Common causes are the wrong selector, the root domain being used instead of the signing domain, a provider CNAME pointing to an inactive target, or a record that has not reached the authoritative zone.

What this checker can prove

This checker shows what public DNS returns for the selectors it detects and whether those records contain usable keys. It cannot prove that it found every selector, that all sending systems sign, that a receiver accepted a particular signature, or that DKIM aligns for DMARC. Those answers require the original headers of a newly delivered message.

Verify DKIM on a real email

Send the same message type through every important production path, preserve the receiver's original source, and read a trusted Authentication-Results header. A dkim=none result normally means that path did not sign. A dkim=fail result requires the recorded reason, selector lookup, and any post-signing content changes. A pass still needs alignment: compare the DKIM d= domain with the visible From domain using the DMARC checker and the message result together.

Related DKIM checks and repairs

Email authentication knowledge base

Can this DKIM tester check every selector?

No. This domain scan reports the selectors it detects, but it may miss a custom selector. Compare the result with the s= selector and d= signing domain in a real message's DKIM-Signature header or the current sending provider configuration.

Does a published DKIM record prove email is being signed?

No. A public key proves that DNS serves a record for that selector. It does not prove that every production sending path adds a signature, uses the same selector, survives message modification, or passes at the receiver. Verify a newly delivered message separately.

What does an empty DKIM p= value mean?

An empty p= value revokes the public key for that selector. A sender still signing with the corresponding private key will fail verification. Confirm that the selector is intentionally retired before removing it or activating a replacement.

Why does DKIM pass but DMARC fail?

DMARC requires the passing DKIM d= domain to align with the visible From domain. DKIM can validate a provider-owned signing domain while DMARC still fails alignment. Compare the exact domains and then configure a custom aligned signature when the provider supports it.

What should I do when a message reports dkim=none?

Check whether the message has a DKIM-Signature header. If it does not, enable DKIM on that exact production path. If it does, confirm you are reading a trusted receiver-added Authentication-Results header and inspect whether the receiver recorded a different authentication result.

Can a DKIM checker guarantee inbox placement?

No. DKIM is one authentication signal. Receivers also evaluate DMARC alignment, SPF, sender and IP reputation, recipient engagement, content, and private policy. A valid record and a passing signature are necessary evidence, not a placement guarantee.