DKIM Key Checker

Look up a domain's DKIM selector and inspect the published public key — is it valid, strong, and out of testing mode? No account required. We run the same engine the OnlyDMARC platform uses.

Enter a domain to check

We'll look up the DKIM key at {selector}._domainkey.{domain} and check whether it's published, valid, strong, and out of testing mode.

May be a subdomain, like mail.example.com.

  Not sure which selector? Look in the s= tag of a DKIM-Signature: header on an email you sent — or leave it blank and we'll probe common selectors for you.

  Free — no account, no sign-up. Runs the same engine as the OnlyDMARC platform. For abuse-prevention we keep only your IP and the domain you check, then anonymise it.

Testing mode (t=y)

Your DKIM key is published but has a weakness worth fixing — see below.
example.com
checked at 12:00 UTC

What to do: Remove t=y once you've confirmed signing works.

Selector s1

key found
Queried s1._domainkey.example.com
  RSA  2048-bit  testing mode (t=y)  sha256
v=DKIM1; k=rsa; t=y; p=MIIBIjAN…
Warning Testing mode (t=y)

t=y puts the key in testing mode: receivers ignore DKIM failures and treat your mail as unsigned.

What to do: Remove t=y once you've confirmed signing works.

Learn more →
Good Strong key (2048-bit RSA)

A parseable RSA key of 2048 bits or more meets current DKIM strength guidance.

What to do: No action needed. Keep monitoring for rotation and drift.

Learn more →

What this check covers

This checks the published key — that it exists, is valid, strong, and not in testing mode. It does not verify a signature over a real message or DMARC alignment (d=From); those need an actual signed email. To confirm end-to-end DKIM and alignment, run a real message through DMARC monitoring.

https://onlydmarc.com/dkim-check?domain=example.com&selector=s1
domain=example.com; selector=s1; code=KeyPublished; checkedAtUtc=2026-01-01T12:00:00.0000000Z

Check the rest of your email authentication

Catch the next DKIM break before your mail does

OnlyDMARC surfaces DKIM, SPF and DMARC drift the moment it happens — so a revoked or weakened key never sits unnoticed.

Start monitoring

Why we warn: we flag real key problems, not upsell bait — this checker is complete and free on its own.