DKIM Record Checker

Don't know your selector? We probe 20 common ones (google, selector1/2, k1, s1…) and verify what we find — key present, not revoked, and long enough.

What DKIM does for your outbound

DKIM cryptographically signs every message you send. Receivers verify the signature against a public key published in your DNS at <selector>._domainkey.<domain>. No valid DKIM = failed authentication at Gmail and Microsoft, and DMARC can't pass on signature alignment either.

Common selectors by provider

ProviderSelector(s)
Google Workspacegoogle
Microsoft 365selector1, selector2
Mailchimp / Mandrillk1, mandrill
SendGrids1, s2
Zohozoho
Postmarkpm

FAQ

What key length should I use?

2048-bit RSA. 1024-bit still passes but is considered weak; 512-bit keys are factorable and effectively broken.

My provider rotated keys and mail started failing — why?

If your DNS still serves the old public key after rotation, signatures stop verifying. This is exactly the drift Aurelius alerts on.

DKIM keys rotate. Records get deleted. Know first.

Aurelius tracks your DKIM selectors on every sweep and alerts when a key disappears or changes. Free for 2 domains.

Start monitoring free

More tools: Domain Grader · SPF Checker · DMARC Checker · Blacklist Checker · DMARC Report Analyzer