The XiaTools DKIM Checker allows you to quickly locate and inspect DomainKeys Identified Mail records for any domain using common selectors or a custom selector. By validating these cryptographic signatures, you can ensure your outgoing messages are properly authenticated and less likely to hit the spam folder.
What is it
DomainKeys Identified Mail (DKIM) is an email authentication method designed to detect email spoofing. It provides a cryptographic mechanism to verify that an email was indeed sent by the domain it claims to originate from, and that the message content was not altered in transit. A DKIM record lives in your domain's DNS settings as a TXT record. It contains a public cryptographic key that receiving mail servers use to verify the digital signature attached to the headers of your outgoing emails.
The XiaTools DKIM Checker queries the Domain Name System for these specific TXT records. Because DKIM relies on a "selector"—a unique identifier defined in the email header to help receiving servers find the correct public key—finding the right record can sometimes be challenging. This tool queries standard default selectors or allows you to input your specific custom selector to retrieve the exact public key configuration currently published on your nameservers.
Why it matters
Email deliverability is vital for modern communication, and mailbox providers like Gmail, Microsoft, and Yahoo strictly enforce authentication standards. Without a valid DKIM setup, your legitimate emails are far more likely to be marked as spam, rejected entirely, or displayed with alarming security warnings in the recipient's inbox.
Furthermore, DKIM is a foundational pillar for DMARC (Domain-based Message Authentication, Reporting, and Conformance). For a DMARC policy to pass via DKIM alignment, the DKIM signature must match the domain found in the visible "From" header of your email. If your DKIM record is misconfigured, expired, or missing entirely, your DMARC alignment will fail for services sending on your behalf, such as your CRM, helpdesk, or bulk email provider. Regularly checking your DKIM configuration ensures your brand reputation stays protected and your emails reach the primary inbox.
How to use this tool
- Navigate to the XiaTools DKIM Checker page in your web browser.
- Enter your domain name into the domain input field, for example,
example.com. - Type your specific DKIM selector into the selector input field if you use a custom one, or leave it blank to test common default selectors.
- Press the Check button to initiate the live DNS query.
- Review the resulting DKIM record status, public key data, and any diagnostic warnings displayed on the screen.
How to read the results
When you run a check for a domain like example.com with a selector such as default, the tool displays the raw DNS query results and parses the components of the record. Here is an explanation of every value you might see in a successful or failed result.
- Status: This indicates whether a valid DKIM TXT record was successfully retrieved from the DNS for the specified selector. A "Success" status means the record exists, while a "Not Found" status means no TXT record was located at
selector._domainkey.example.com. - Selector: The specific string identifier you tested, such as
defaultorgoogle. It confirms which sub-domain path was queried. - DNS Hostname: The full DNS query path, constructed as
selector._domainkey.example.com. This is where receiving mail servers look for your public key. - Record Type: Typically listed as
TXT. DKIM records must be published as TXT records in your DNS zone. - Version (v): Defined inside the record data, usually set to
v=DKIM1. This tells the receiving server which version of the protocol the key is using. - Public Key Data (p): The core cryptographic payload, represented by a long string of characters preceded by
p=. For example,p=MIIBIjANBgkqhkiG9w0BAQFAAOCAQ8AMIIBCgKCAQEA.... This is the public key that matches the private key held by your email sender. - Granular Flags (t, k, s): Optional tags that define behavior. For instance,
t=yindicates the domain is in test mode, meaning receiving servers should not reject emails even if the signature fails. A missingt=tag implies the record is live in production.
Common problems and how to fix them
Missing DKIM Record
If the tool reports that no record was found, your DNS provider does not have the necessary TXT record published for that selector. Log into your DNS management console and add the record provided by your email service provider.
selector._domainkey.example.com. IN TXT "v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG..."
Syntax Errors in the Public Key
Typos, missing quotation marks, or accidental line breaks within the p= value will cause verification failures. Ensure the entire public key string is pasted cleanly into your DNS provider's TXT value field without truncation.
Selector Mismatch
If your email headers use a selector like s1 but you published your record under the default selector, receiving servers will fail to find the key. Verify the exact selector string required by your email sending platform and ensure it matches your DNS entry.
Exceeded Character Limits
Public keys often exceed the standard 255-character limit for a single DNS string. If your DNS provider does not automatically handle string concatenation, you may need to split the key into multiple quoted strings within the same TXT record.
selector._domainkey.example.com. IN TXT "v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQFA..." "...OCAQ8AMIIBCgKCAQEA..."
Best practices
Maintain robust email security by rotating your DKIM keys periodically, typically once a year, to minimize the risk of cryptographic compromise. Always use the key length recommended by your email provider, favoring 2048-bit keys over older 1024-bit keys for stronger security. When implementing a new key, keep the old selector active temporarily during the transition period to prevent mail delivery failures for inflight messages. Finally, pair your DKIM setup with properly configured SPF and DMARC records to establish comprehensive domain authentication and visibility.