DKIM

Check your DKIM keys.

DKIM signs your mail so receivers can prove it was not altered and really came from you. This checker scans 22 common selectors and grades the key strength it finds.

DNS lookups only. We never touch your site or your mail.

Questions

The details.

What is a DKIM selector and why does the scan need to guess?

DKIM keys live at selector._domainkey.yourdomain.com, and the selector name is chosen by your email provider \u2014 Google Workspace uses “google”, Microsoft uses selector1/selector2, many ESPs use k1 or s1. There is no way to list a domain's selectors from outside, so this checker scans 22 common ones, including the date-style selectors a few providers publish. A clean scan is strong evidence of missing DKIM, not absolute proof.

What key length should DKIM use?

2048-bit RSA. 1024-bit keys still pass validation but are legacy strength, and providers have had shorter keys cracked and spoofed. If this scan flags a 1024-bit key, rotate it \u2014 your provider's dashboard almost always offers 2048 now.

Does DKIM matter if SPF already passes?

Yes. SPF breaks on forwarding; DKIM survives it. DMARC needs only one of the two to pass IN ALIGNMENT with your From domain, so running both is what keeps legitimate mail deliverable when one mechanism fails.