Look up a domain's DKIM selector and inspect the published public key — is it valid, strong, and out of testing mode? No account required. We run the same engine the OnlyDMARC platform uses.
We'll look up the DKIM key at {selector}._domainkey.{domain} and check whether it's
published, valid, strong, and out of testing mode.
Not sure which selector? Look in the s= tag of a DKIM-Signature: header on an
email you sent — or leave it blank and we'll probe common selectors for you.
Free — no account, no sign-up. Runs the same engine as the OnlyDMARC platform. For abuse-prevention we keep only your IP and the domain you check, then anonymise it.
What to do: Remove t=y once you've confirmed signing works.
v=DKIM1; k=rsa; t=y; p=MIIBIjAN…t=y puts the key in testing mode: receivers ignore DKIM failures and treat your mail as unsigned.
What to do: Remove t=y once you've confirmed signing works.
Learn more →A parseable RSA key of 2048 bits or more meets current DKIM strength guidance.
What to do: No action needed. Keep monitoring for rotation and drift.
Learn more →
This checks the published key — that it exists, is valid, strong, and not in testing mode.
It does not verify a signature over a real message or DMARC alignment
(d= ↔ From); those need an actual signed email. To confirm end-to-end DKIM and
alignment, run a real message through DMARC monitoring.
https://onlydmarc.com/dkim-check?domain=example.com&selector=s1domain=example.com; selector=s1; code=KeyPublished; checkedAtUtc=2026-01-01T12:00:00.0000000ZOnlyDMARC surfaces DKIM, SPF and DMARC drift the moment it happens — so a revoked or weakened key never sits unnoticed.
Start monitoringWhy we warn: we flag real key problems, not upsell bait — this checker is complete and free on its own.