All tools

DKIM Record Checker

Find a domain’s email-signing public key using its DKIM selector.

Use d= for the domain and s= for the selector from an email’s DKIM-Signature header.

In an email’s DKIM-Signature header, use the value after s=.

Enter a value above to start. No account needed.

How this check works

We query selector._domainkey.domain, combine TXT chunks, inspect the key tags and attempt to parse supported RSA or Ed25519 public keys.

What this check does not prove

A published key does not prove that outgoing messages are signed correctly. This checks the exact selector you provide; there is no reliable way to discover every selector from a domain alone.

Where do I find the selector?

Open the original message or source in your email app. In DKIM-Signature, s= gives the selector and d= gives the signing domain. Your email provider may also list them in its setup instructions.

Why does my provider give me a CNAME?

Some providers host the signing key for you. A CNAME at the selector name points to their key; DNS normally follows it when retrieving the TXT record.