XiaTools
Email tool

DKIM Checker

Find DKIM records for common selectors or check a specific selector for any domain.

The XiaTools DKIM Checker allows you to quickly locate and inspect DomainKeys Identified Mail records for any domain using common selectors or a custom selector. By validating these cryptographic signatures, you can ensure your outgoing messages are properly authenticated and less likely to hit the spam folder.

What is it

DomainKeys Identified Mail (DKIM) is an email authentication method designed to detect email spoofing. It provides a cryptographic mechanism to verify that an email was indeed sent by the domain it claims to originate from, and that the message content was not altered in transit. A DKIM record lives in your domain's DNS settings as a TXT record. It contains a public cryptographic key that receiving mail servers use to verify the digital signature attached to the headers of your outgoing emails.

The XiaTools DKIM Checker queries the Domain Name System for these specific TXT records. Because DKIM relies on a "selector"—a unique identifier defined in the email header to help receiving servers find the correct public key—finding the right record can sometimes be challenging. This tool queries standard default selectors or allows you to input your specific custom selector to retrieve the exact public key configuration currently published on your nameservers.

Why it matters

Email deliverability is vital for modern communication, and mailbox providers like Gmail, Microsoft, and Yahoo strictly enforce authentication standards. Without a valid DKIM setup, your legitimate emails are far more likely to be marked as spam, rejected entirely, or displayed with alarming security warnings in the recipient's inbox.

Furthermore, DKIM is a foundational pillar for DMARC (Domain-based Message Authentication, Reporting, and Conformance). For a DMARC policy to pass via DKIM alignment, the DKIM signature must match the domain found in the visible "From" header of your email. If your DKIM record is misconfigured, expired, or missing entirely, your DMARC alignment will fail for services sending on your behalf, such as your CRM, helpdesk, or bulk email provider. Regularly checking your DKIM configuration ensures your brand reputation stays protected and your emails reach the primary inbox.

How to use this tool

  1. Navigate to the XiaTools DKIM Checker page in your web browser.
  2. Enter your domain name into the domain input field, for example, example.com.
  3. Type your specific DKIM selector into the selector input field if you use a custom one, or leave it blank to test common default selectors.
  4. Press the Check button to initiate the live DNS query.
  5. Review the resulting DKIM record status, public key data, and any diagnostic warnings displayed on the screen.

How to read the results

When you run a check for a domain like example.com with a selector such as default, the tool displays the raw DNS query results and parses the components of the record. Here is an explanation of every value you might see in a successful or failed result.

Common problems and how to fix them

Missing DKIM Record

If the tool reports that no record was found, your DNS provider does not have the necessary TXT record published for that selector. Log into your DNS management console and add the record provided by your email service provider.

selector._domainkey.example.com. IN TXT "v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG..."

Syntax Errors in the Public Key

Typos, missing quotation marks, or accidental line breaks within the p= value will cause verification failures. Ensure the entire public key string is pasted cleanly into your DNS provider's TXT value field without truncation.

Selector Mismatch

If your email headers use a selector like s1 but you published your record under the default selector, receiving servers will fail to find the key. Verify the exact selector string required by your email sending platform and ensure it matches your DNS entry.

Exceeded Character Limits

Public keys often exceed the standard 255-character limit for a single DNS string. If your DNS provider does not automatically handle string concatenation, you may need to split the key into multiple quoted strings within the same TXT record.

selector._domainkey.example.com. IN TXT "v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQFA..." "...OCAQ8AMIIBCgKCAQEA..."

Best practices

Maintain robust email security by rotating your DKIM keys periodically, typically once a year, to minimize the risk of cryptographic compromise. Always use the key length recommended by your email provider, favoring 2048-bit keys over older 1024-bit keys for stronger security. When implementing a new key, keep the old selector active temporarily during the transition period to prevent mail delivery failures for inflight messages. Finally, pair your DKIM setup with properly configured SPF and DMARC records to establish comprehensive domain authentication and visibility.

Frequently asked questions

What is a DKIM selector?

A DKIM selector is a unique string used to identify a specific public key in your domain's DNS. Because a single domain may send mail from multiple services like Google Workspace or Mailchimp, selectors allow receiving servers to locate the correct key for the specific service that sent the email.

Why does the tool say my DKIM record was not found?

This usually happens when the TXT record has not been published in your DNS settings, or when you are testing the wrong selector name. Double-check your DNS provider to ensure the record exists at the exact path `selector._domainkey.yourdomain.com`.

What key length should I use for DKIM?

You should use a 2048-bit RSA key whenever your DNS provider supports it. While 1024-bit keys are still functional, 2048-bit keys provide a much higher level of cryptographic security and are standard practice for modern email infrastructure.

Can I have multiple DKIM records for one domain?

Yes, absolutely. You can have as many DKIM records as you have selectors. This is common when a domain utilizes multiple third-party email vendors, as each vendor requires its own unique selector and public key.

How long does it take for DNS changes to update?

DNS propagation typically takes anywhere from a few minutes up to 24 hours, depending on your DNS host's Time To Live (TTL) settings. If you just added your DKIM record, you might need to wait a short while before the tool can successfully detect it.

Does this tool check my SPF and DMARC records too?

No, this tool focuses exclusively on finding and validating DKIM records and their associated public keys. To check your SPF or DMARC policies, you should use the dedicated SPF and DMARC lookup tools available on XiaTools.

DKIM Checker guides

Related tools