All systems operationalReal-time DNS, email and infrastructure monitoring
SupportAPIContactSign in

DKIM Lookup

Look up and validate a DKIM public key for a selector, including key length and flags.

About the DKIM Lookup

DKIM signs outgoing messages with a private key; receivers verify the signature using the public key published at selector._domainkey.yourdomain.com. Because the selector is chosen by the signing system, you need to know it — common values are google (Google Workspace), selector1/selector2 (Microsoft 365), k1 (Mailchimp), s1/s2 (SendGrid) or mandrill. The selector is also visible in the s= tag of any DKIM-Signature header, which the Header Analyzer extracts for you.

The tool follows CNAME delegations, decodes the public key, reports its type and length, and flags revoked (empty) keys, testing flags and weak hash settings.

Recommendations

  • Use 2048-bit RSA keys; 1024-bit is the minimum accepted.
  • Rotate keys at least yearly by publishing a new selector.
  • Sign with the domain in the visible From header so DMARC aligns.

Monitor this automatically

Get alerted when this check starts failing, when you land on a blacklist or when a certificate or domain is about to expire.

Start free monitoring