DKIM Record Checker

DKIM signs outgoing emails. Receivers verify the signature using a public key in DNS.

DKIM lives on <selector>._domainkey.<domain>. If selector is empty, we try common ones.

Result for discover.com

Found
Selector: default (TXT on default._domainkey.discover.com)
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxf6SCaZIEsIu62n2voxAV0JLNF5Z4/Fhxy/0wuoja7FT1I9irGP7hmF7UdRLu1smWmfdAOJTFXmLmX53ct1ShwWy77fZKkxFBQ6qnwrBMhhKnTPJ9CrUQ3Sgu6mT24K50kd6QB3v86UXdQRGA82HLqMA0YefzXEvwdPAxr7bbVmzlaeo2yoQxlz7UGUsd/44Fy48BtVun1mbdtevD2ZCcFp0O3ZZhNUagGKWQVdsEEJWoGTMNSdk08U37oMrdyTlNmJNgQTGpCYpbw/q9Qd8p5HaY5hC7VD5YhTcAgh0QjY1kUnY+CwVm7xAtXBs5WdB5EmUOq+87omnrvG1K22EVQIDAQAB
Selector: selector1 (TXT on selector1._domainkey.discover.com)
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCsmEyfHdpc0b1WrKnLGQ9ZmoWET4tlC7ZLylRJE4LCIpTRJC18qpsgPG7p/lh5x2+k8vF2N25SfcVn5TkPoAmc59FbndLp3UNU8rrPlZrSiyQ5MHGD5Rg5pYrsbHd7o4eSbI1S2nSB1uX7xFsGPCacDWYa172pkk/Vq3WYnnjQrQIDAQAB; n=1024,1442021780,1457746580
Selector: selector2 (TXT on selector2._domainkey.discover.com)
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDEwOQ2dUF7RALUC5q3QoReom/g3B3ARpz81DfhAzDa/Run8rY9Kk7uj2Jm5YMOix1vLCXgK+bkhYIYASrratIId1KeO8ofJ1Tcsg90I+ACNzhHlfA+s9SVq0/KTP7Uzvb9YRaoBNkPCd9vyj2CbtyTeCG7cdsOzZyisJBtJWaAbQIDAQAB; n=1024,1442021780,1457746580

FAQ

Why does DKIM require a selector?
Selectors allow rotating keys and running multiple keys per domain.
Where is DKIM published?
TXT on <selector>._domainkey.<domain>.
DKIM record exists but emails still fail DKIM?
Signing may be disabled or the selector used in email differs from DNS.
Do I need DKIM if I have SPF?
Yes, many providers use both for best deliverability and DMARC alignment.
Can I have multiple DKIM selectors?
Yes, that is common for key rotation or multiple senders.

What is DKIM?

DKIM (DomainKeys Identified Mail) adds a cryptographic signature to outgoing emails. DNS stores a public key that allows receivers to verify authenticity.

Example

v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0B...

Common mistakes

  • Wrong selector (the record exists but under a different selector).
  • Key is split incorrectly across multiple TXT chunks (some DNS UIs break it).
  • Publishing DKIM but not enabling signing on the mail provider.