DNS & EMAIL

DKIM Record Checker

Query selector._domainkey.domain and check for a DKIM TXT or CNAME record.

39DExternal testRuns from the toolbox server

RUN TEST

DKIM Record Checker

Public targets only

HOW IT WORKS

About the DKIM Record Checker

DKIM uses a private key to sign selected email headers. Receiving systems retrieve the matching public key from DNS using the selector carried in the signature.

How to use this result

  1. Run the test from this server.Use a public hostname, address, prefix or ASN in the format requested above.
  2. Compare with another observation point.Run a local command or use a second provider to identify location-specific behaviour.
  3. Correlate related evidence.Use the related tools below to compare DNS, routes, ports, TLS and application responses.
  4. Keep the time and context.Routing, DNS caches and reputation data change, so record when the result was collected.

Common interpretation issues

  • A selector can be a CNAME to a hosted mail provider.
  • Whitespace or truncated TXT values can make copied keys look incorrect.
  • Rotated selectors may coexist while old mail remains in transit.

NEED HELP INTERPRETING THE RESULT?

39D supports business networks, cyber security and managed IT.

For ongoing support or a larger infrastructure project, speak to the 39D team.

Visit 39D

Frequently asked questions

Where do I find the selector?

It appears in the DKIM-Signature header as the s= value.

Can there be more than one selector?

Yes. Multiple selectors are common during key rotation or when several platforms send mail.