DKIM Record Checker

DKIM signs outgoing emails. Receivers verify the signature using a public key in DNS.

DKIM lives on <selector>._domainkey.<domain>. If selector is empty, we try common ones.

Result for tomshardware.com

Found
Selector: selector1 (TXT on selector1._domainkey.tomshardware.com)
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCuz4RJhGJFk42yVok0w+Paub9PpytVC5rfDS/MzK2K/26nogQz1IZMOKm5XXX/FzhUCeKvNQHwtMympK77VyZ92vE+1Hp2MTjvifc/ZVxCwFHPiit+vX1I2F5Xq5Cw7zDfORlH0JmiSF8gNDaiEnSCPKkQkVbWT8CSapBDEmK8jwIDAQAB; n=1024,1457669433,1
Selector: selector2 (TXT on selector2._domainkey.tomshardware.com)
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCd8askRUJBTL0XgfFLuV/qx7q/Uk4WBPAVDFLODRw5BOD9MqqWhXYgThS7kEErdgPymt9lQTx4niv3ZAiB3IqAW0EZ0Ify/WB/YV1qoj9xcBgYt3Fcz+vNAuvTqMoZUyJjew5R4QjaDN7BbeslhM3A1vgLXgYn/OD79OJCPhjNAQIDAQAB;
Selector: google (TXT on google._domainkey.tomshardware.com)
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqSTQMUnepeLH3lxIpW6FGQKgtZm4o2hIdYy2DCkxm7birVeUhRAR0kvGzt0xDZMrhGRnNVWxD+NplEZLW6AhjsfVY/utsLkmgjfr9Vs41jlMSP+X+Hz4U1ALOMFKMfiOe48/zsbbCR9TI8AX7jg0Lut4Xw0GQvwZ/gxa16eWNTW8m6VGPzUzc1u4tFplojzLvz7TCn+WxFATX+hAGGsr61/yB4l/mgBrPAQUNEED16Rg0OReKifNPLcRe2eApYt1/YhPebR08Es5ExAZP3LRH87Vg+M6elwb6DUMmx4XFjdBSft+t9fdxbXkA+o2xPitRtpIhyTaR63OJ64ot9aEIQIDAQAB

FAQ

Why does DKIM require a selector?
Selectors allow rotating keys and running multiple keys per domain.
Where is DKIM published?
TXT on <selector>._domainkey.<domain>.
DKIM record exists but emails still fail DKIM?
Signing may be disabled or the selector used in email differs from DNS.
Do I need DKIM if I have SPF?
Yes, many providers use both for best deliverability and DMARC alignment.
Can I have multiple DKIM selectors?
Yes, that is common for key rotation or multiple senders.

What is DKIM?

DKIM (DomainKeys Identified Mail) adds a cryptographic signature to outgoing emails. DNS stores a public key that allows receivers to verify authenticity.

Example

v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0B...

Common mistakes

  • Wrong selector (the record exists but under a different selector).
  • Key is split incorrectly across multiple TXT chunks (some DNS UIs break it).
  • Publishing DKIM but not enabling signing on the mail provider.