DKIM Key Checker

Look up a domain's DKIM selector and inspect the published public key — is it valid, strong, and out of testing mode? No account required. We run the same engine the OnlyDMARC platform uses.

Enter a domain to check

We'll look up the DKIM key at {selector}._domainkey.{domain} and check whether it's published, valid, strong, and out of testing mode.

May be a subdomain, like mail.example.com.

  Not sure which selector? Look in the s= tag of a DKIM-Signature: header on an email you sent — or leave it blank and we'll probe common selectors for you.

  Free — no account, no sign-up. Runs the same engine as the OnlyDMARC platform. For abuse-prevention we keep only your IP and the domain you check, then anonymise it.

DKIM key looks good

Your DKIM key is published, valid, and within current strength guidance.
example.com
checked at 12:00 UTC

Selector s1

key found
Queried s1._domainkey.example.com
  RSA  2048-bit  sha256
v=DKIM1; k=rsa; p=MIIBIjAN…
Good Strong key (2048-bit RSA)

A parseable RSA key of 2048 bits or more meets current DKIM strength guidance.

What to do: No action needed. Keep monitoring for rotation and drift.

Learn more →

What this check covers

This checks the published key — that it exists, is valid, strong, and not in testing mode. It does not verify a signature over a real message or DMARC alignment (d=From); those need an actual signed email. To confirm end-to-end DKIM and alignment, run a real message through DMARC monitoring.

https://onlydmarc.com/dkim-check?domain=example.com&selector=s1
domain=example.com; selector=s1; code=KeyPublished; checkedAtUtc=2026-01-01T12:00:00.0000000Z

Check the rest of your email authentication

Keep it healthy — monitor for drift

Keys rotate and providers change. OnlyDMARC watches your DKIM, SPF and DMARC around the clock and alerts you when something moves.

Start monitoring

Why we warn: we flag real key problems, not upsell bait — this checker is complete and free on its own.