Don't know your selector? We probe 20 common ones (google, selector1/2, k1, s1…) and verify what we find — key present, not revoked, and long enough.
DKIM cryptographically signs every message you send. Receivers verify the signature against a public key published in your DNS at <selector>._domainkey.<domain>. No valid DKIM = failed authentication at Gmail and Microsoft, and DMARC can't pass on signature alignment either.
| Provider | Selector(s) |
|---|---|
| Google Workspace | google |
| Microsoft 365 | selector1, selector2 |
| Mailchimp / Mandrill | k1, mandrill |
| SendGrid | s1, s2 |
| Zoho | zoho |
| Postmark | pm |
2048-bit RSA. 1024-bit still passes but is considered weak; 512-bit keys are factorable and effectively broken.
If your DNS still serves the old public key after rotation, signatures stop verifying. This is exactly the drift Aurelius alerts on.
More tools: Domain Grader · SPF Checker · DMARC Checker · Blacklist Checker · DMARC Report Analyzer