Look up a domain's DKIM selector and inspect the published public key — is it valid, strong, and out of testing mode? No account required. We run the same engine the OnlyDMARC platform uses.
We'll look up the DKIM key at {selector}._domainkey.{domain} and check whether it's
published, valid, strong, and out of testing mode.
Not sure which selector? Look in the s= tag of a DKIM-Signature: header on an
email you sent — or leave it blank and we'll probe common selectors for you.
Free — no account, no sign-up. Runs the same engine as the OnlyDMARC platform. For abuse-prevention we keep only your IP and the domain you check, then anonymise it.
What to do: Republish the public key, or point mail at a live selector.
Multiple common selectors published an identical key — often a provider default. We've collapsed the duplicates below so you see each distinct key once.
v=DKIM1; p=This selector's key is revoked (empty p=). Every signature using it fails.
What to do: Republish the public key, or point mail at a live selector.
The published key is empty, so every DKIM signature using it fails — mail may be rejected or land in spam. Republish a real key or switch to a working selector.
This checks the published key — that it exists, is valid, strong, and not in testing mode.
It does not verify a signature over a real message or DMARC alignment
(d= ↔ From); those need an actual signed email. To confirm end-to-end DKIM and
alignment, run a real message through DMARC monitoring.
https://onlydmarc.com/dkim-check?domain=example.comdomain=example.com; selector=(auto); code=KeyProblem; checkedAtUtc=2026-07-25T15:33:39.8523610ZOnlyDMARC surfaces DKIM, SPF and DMARC drift the moment it happens — so a revoked or weakened key never sits unnoticed.
Start monitoringWhy we warn: we flag real key problems, not upsell bait — this checker is complete and free on its own.