Skip to content
EMPRAOUTBOUND
The engineDeliverabilityMethod
SignalsOutreach fired the week something changes.LinkedInThe other half of outbound, on one clock.Reply agentEvery reply answered in 30 minutes.AutomationsWhat happens the second a reply lands.
Find your marketScale outboundNew marketsHiringInvestorsRe-engageEvents
Grade my emailApply

CORE

The engineDeliverabilityMethod

EXTENSIONS

SignalsLinkedInReply agentAutomations

MISSIONS

Find your marketScale outboundNew marketsHiringInvestorsRe-engageEvents

FREE

Grade my emailApply

EMPRA

EMPRA

Outbound

RUN BY HUGO DUPONT & GEORGE LEVESON
LONDON

Empra Outbound is a done-for-you cold outbound firm in London, run by its two co-founders, whose writing model is trained on 4,000,000 cold emails the team sent over three years.

WHAT WE RUN

  • The engine
  • Deliverability
  • Method
  • EXTENSIONS
  • Signals
  • LinkedIn
  • Reply agent
  • Automations

MISSIONS

  • Find your market
  • Scale outbound
  • New markets
  • Hiring
  • Investors
  • Re-engage
  • Events

FREE TOOLS

  • Grade my email
  • Deliverability test
  • SPF checker
  • DKIM checker
  • DMARC checker
  • Subject line tester
  • Spam checker

THE PLAYBOOK

  • Playbook overview
  • Subject lines
  • The ask
  • The sequence
  • Follow-ups
  • Identify your ICP
  • Infrastructure

COMPANY

  • Cold email agency
  • Agency shortlist
  • Agency vs DIY
  • Blog
  • About
  • Start a build

Every figure on this site is a count of work we have done. Pipeline and closed revenue are our clients’ results, and results vary. Replies are shown as they arrived, with senders blurred at source.

DKIM

Check your DKIM keys.

This checker scans your domain’s DNS for DKIM keys at 22 common selector prefixes and passes when it finds a 2048-bit key, meaning mail signed with it can be verified by receivers as unaltered and genuinely from you.

DNS lookups only. We never touch your site or your mail.

Questions

The details.

What is a DKIM selector and why does the scan need to guess?

DKIM keys live at selector._domainkey.yourdomain.com, and the selector name is chosen by your email provider: Google Workspace uses “google”, Microsoft uses selector1/selector2, many ESPs use k1 or s1. There is no way to list a domain's selectors from outside, so this checker scans 22 common ones, including the date-style selectors a few providers publish. A clean scan is strong evidence of missing DKIM, not absolute proof.

What key length should DKIM use?

2048-bit RSA. 1024-bit keys still pass validation but are legacy strength, and providers have had shorter keys cracked and spoofed. If this scan flags a 1024-bit key, rotate it. Your provider's dashboard almost always offers 2048 now.

Does DKIM matter if SPF already passes?

Yes. SPF breaks on forwarding; DKIM survives it. DMARC needs only one of the two to pass IN ALIGNMENT with your From domain, so running both is what keeps legitimate mail deliverable when one mechanism fails.

What does it mean if my DKIM check passes?

A pass means this scan found a DKIM key at one of the 22 selectors it checks and the key is 2048-bit, which meets current strength recommendations.

What does a DKIM failure mean?

A failure means the scan found no key at any of the 22 selectors it checks, or found one that is only 1024-bit, which is legacy strength; because selectors cannot be listed from outside, a clean scan is strong evidence of missing DKIM rather than absolute proof.

What should I do if my DKIM check fails?

Turn on DKIM signing in your email provider's dashboard, publish the key it gives you as a TXT record at selector._domainkey.yourdomain.com, and rotate any 1024-bit key to 2048-bit if your provider offers it.

Free

Grade the email you are about to send.

Paste it, and the rule-set from 4,000,000 sends scores it. The report lands in your inbox in minutes, and a full three-step sequence written for your ICP follows from Hugo a few hours later.

Grade my email