Free DKIM Checker & Generator

Check the DKIM records your domain publishes, with the key type, key length and anything receivers will object to. Need a new key? Generate one below. It never leaves your browser.

Check your DKIM record

Enter your domain. Add the selector if you know it. Leave it blank and we try the selectors common providers use.

Generate a DKIM key pair

Most email providers create the key for you and hand you the DNS record. Use this when you sign mail yourself, for example Postfix with OpenDKIM. The key is created in your browser and never sent to us.

Understanding DKIM

What is DKIM?

DKIM (DomainKeys Identified Mail) adds a cryptographic signature to every message you send. Your mail server signs with a private key. Receivers fetch the matching public key from your DNS and check the signature. If it verifies, they know the message came from a server you control and wasn't changed on the way.

Gmail, Yahoo and Microsoft expect DKIM on bulk mail. For DMARC to pass on DKIM, the signing domain also has to match your From domain. That is DKIM alignment.

Selectors used by common providers

Provider Selector
Google Workspace google
Microsoft 365 selector1, selector2
Mailchimp k1, k2, k3
SendGrid s1, s2
Klaviyo kl, kl2
Resend resend
Fastmail fm1, fm2, fm3
Proton Mail protonmail, protonmail2, protonmail3
Amazon SES Three random tokens, shown in the SES console

Providers change these over time. The DKIM-Signature header on a real message is always the source of truth.

What a DKIM record looks like

A TXT record at mail._domainkey.example.com:

v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...

v is the version, k the key type and p the public key. An empty p= means the key was revoked. t=y marks it as testing.

What is a DKIM selector?

A selector is the name that tells receivers which DKIM key to fetch. The key lives at selector._domainkey.yourdomain.com. One domain can have many selectors, usually one per service that sends for it, so each provider can sign with its own key.

How do I find my DKIM selector?

Open an email you sent, view the original message or raw source, and find the DKIM-Signature header. The s= tag is the selector and d= is the signing domain. You can also leave the selector blank above and we will try the ones common providers use.

Should I use a 1024-bit or 2048-bit DKIM key?

Use 2048 bits. 1024-bit keys still pass today, but they are the minimum, and the major mailbox providers recommend 2048. Keys shorter than 1024 bits are treated as insecure and may be ignored.

Why is my DKIM record too long for DNS?

A 2048-bit key makes a TXT value of about 400 characters, and a single DNS string holds 255. The record has to be split into two quoted strings inside one TXT record. Most DNS providers split it for you when you paste the full value.

Does DKIM survive email forwarding?

Usually, yes. The signature travels with the message, so it still verifies after a plain forward. It breaks when a forwarder or mailing list changes the signed parts, such as the subject line or body.

Is the private key sent to your server?

No. The generator uses your browser's built-in Web Crypto API. The key pair is created on your device and never leaves it. Close the tab and it is gone, so copy the private key somewhere safe first.

DKIM is one of three records. Run your domain through the DMARC checker to check SPF, DKIM and DMARC together.

Own your email platform

Broadcast is self-hosted email marketing software. It watches your SPF, DKIM and DMARC records and tells you when one breaks. Pay once, run it on your own server.