Free Tools

DKIM Record Checker

Paste the headers of a message you sent. We find every DKIM signature on it, check the key each one uses, and whether any of them aligns with your From address.

The headers are read in your browser. We only receive your From domain and the DKIM tags we check: d=, s=, a=, the domain in i=, h=, l= and x=. Addresses, subjects and signatures stay with you.

What this checks

Receivers verify a DKIM signature against a public key published at selector._domainkey.yourdomain.com. This finds those keys and checks each one the way a receiver reads it: that it parses, that it is long enough, that it has not been revoked, and that nothing in the record tells receivers to ignore it.

A published, valid key is not the same as mail that passes DKIM. That also needs your provider to sign with it, using your domain. To see what a real message was signed with, check its headers.

Your keys are published. Are they the ones your mail is signed with?

DNS can't tell you. DMARC aggregate reports record the selector and the DKIM result for every message receivers saw from your domain. Report URI collects and reads them for you.