About DKIM Checker
Run the DKIM checker after you turn on signing in Google Workspace, Microsoft 365 or a newsletter service, when DMARC reports show DKIM failing, or before you rotate a key. DKIM keys live at selector._domainkey.yourdomain, and DNS can't list them, so the selector matters. Type it under Selector (optional), or leave it empty and the tool tries about 45 common ones, such as google, selector1, selector2, k1, s1, default and Google's date-based selectors like 20230601.
For every key found you see the algorithm, RSA or Ed25519, and its length. Keys under 2048 bits get a warning and keys under 1024 bits fail, because many receivers reject them. Revoked keys with an empty p=, keys that can't be read and keys in test mode (t=y) are flagged too. The checker reads the published keys, not a signed message. To see which domain and selector actually signed an email, paste its headers into the Email Header Analyzer.
How to use DKIM Checker
- 1Enter the domain
Type the domain you send from, or paste an email address.
- 2Add the selector if you know it
Find it as s= in the DKIM-Signature header of a message you sent, or leave the box empty.
- 3Run the DKIM checker
Click Check, and without a selector about 45 common names are tried at once.
- 4Read each key
The table shows selector, algorithm, bits and state, and you can copy it or save it as CSV.
Why use Cubfile for this
- Selector auto-detect
About 45 common selectors are tried when you don't enter one.
- Key length check
A warning under 2048 bits and a fail under 1024.
- RSA and Ed25519
The algorithm and size are read from the public key itself.
- State of each key
Revoked, unreadable and test-mode keys are flagged.