Look up and validate the DKIM public key of a domain and selector.
The DKIM checker looks up the DKIM public key of a domain at selector._domainkey.domain. Enter the selector, or leave it empty to try the selectors of the common email providers such as Google Workspace, Microsoft 365, Zoho, Mailchimp and others.
It checks that the record is valid, measures the key size – 2048 bits is the recommended minimum – and flags revoked keys and testing mode.
Tries about 40 common selectors when you don't know yours.
Reads the RSA key and reports its length.
Revoked keys, testing mode and version.
Copy the DKIM record.
A name that points to one of the domain's DKIM keys. It's the s= value in the DKIM-Signature header of an email.
Open an email sent from your domain, view the original message and look for s= in the DKIM-Signature header.
2048-bit RSA. 1024-bit keys still work but are considered weak.