Look up a domain's DKIM selector and inspect the published public key — is it valid, strong, and out of testing mode? No account required. We run the same engine the OnlyDMARC platform uses.
We'll look up the DKIM key at {selector}._domainkey.{domain} and check whether it's
published, valid, strong, and out of testing mode.
Not sure which selector? Look in the s= tag of a DKIM-Signature: header on an
email you sent — or leave it blank and we'll probe common selectors for you.
Free — no account, no sign-up. Runs the same engine as the OnlyDMARC platform. For abuse-prevention we keep only your IP and the domain you check, then anonymise it.
v=DKIM1; k=rsa; p=MIIBIjAN…A parseable RSA key of 2048 bits or more meets current DKIM strength guidance.
What to do: No action needed. Keep monitoring for rotation and drift.
Learn more →
This checks the published key — that it exists, is valid, strong, and not in testing mode.
It does not verify a signature over a real message or DMARC alignment
(d= ↔ From); those need an actual signed email. To confirm end-to-end DKIM and
alignment, run a real message through DMARC monitoring.
https://onlydmarc.com/dkim-check?domain=example.com&selector=s1domain=example.com; selector=s1; code=KeyPublished; checkedAtUtc=2026-01-01T12:00:00.0000000ZKeys rotate and providers change. OnlyDMARC watches your DKIM, SPF and DMARC around the clock and alerts you when something moves.
Start monitoringWhy we warn: we flag real key problems, not upsell bait — this checker is complete and free on its own.