DKIM checker
Probe about 40 common DKIM selectors, or enter your own selector to test it. Free, no signup.
How this DKIM check works
DKIM public keys live at <selector>._domainkey.yourdomain.com, and DNS has no way to list them, so the selector has to be known or guessed. We look up about 40 selectors that common providers use (Google Workspace uses google, Microsoft 365 uses selector1/selector2, Mailchimp k1–k3, SendGrid s1/s2, and others), plus any selector you enter.
Honest results: if no key is found at common selectors, we say so and leave DKIM out of the score. "Not found" does not prove DKIM is missing. If you enter your own selector and no key exists there, the check fails, because mail signed with it will fail DKIM.
Frequently asked questions
What is DKIM?
DKIM (DomainKeys Identified Mail) adds a cryptographic signature to each email. Receivers fetch the public key from DNS at selector._domainkey.yourdomain.com and verify that the message was really sent by your domain and was not changed in transit.
How do I find my DKIM selector?
Open an email you sent, view the original message or headers, and find the DKIM-Signature header. The s= value is the selector and d= is the signing domain. Enter that selector above to test it.
Why does the checker say "not found (inconclusive)"?
Some providers, such as Amazon SES, Salesforce and some Google domains, use random or dated selector names that cannot be guessed. Without the selector, nobody can look up the key, so we do not count it against you.
What does an empty p= mean?
A DKIM record with an empty p= value means the key has been revoked. It is correct for retired selectors, and for domains that never send email.
How do I set up DKIM for Google Workspace or Microsoft 365?
Google Workspace: Admin console > Apps > Google Workspace > Gmail > Authenticate email, generate a key, add the TXT record, then click Start authentication. Microsoft 365: Microsoft Defender portal > Email authentication settings > DKIM, then publish the two CNAME records it shows and enable signing.
Is a 1024-bit DKIM key still OK?
2048-bit keys are recommended today. Many providers still use 1024-bit keys, which are accepted, but rotate to 2048-bit when your provider supports it.
How StackGrade works
Email authentication · 50 pts
SPF (including the 10-lookup limit), DMARC policy, DKIM keys at common selectors, and MX. These decide whether Gmail and Yahoo trust your mail, and whether scammers can spoof you.
Website security · 35 pts
HTTPS redirect, HSTS, Content-Security-Policy, clickjacking protection, X-Content-Type-Options, Referrer-Policy and cookie flags, using Mozilla's public HTTP Observatory scan.
Domain health · 15 pts
Expiry date and registrar transfer lock from the official registry (RDAP). Domain age, email provider, tech stack and hiring signals are shown but not scored.
Honest by design
If a check can't run (the registry has no RDAP, the site blocks scanners, a lookup times out), we show Not checked with the reason and leave it out of the score. We never guess. The full rubric is public.
Privacy
The checks run in your browser, which asks public services directly: Google Public DNS / Cloudflare DNS, the domain's registry RDAP server, Mozilla HTTP Observatory (its scan history is public) and public job boards (Greenhouse, Lever, Ashby, Workable). For the tech-stack scan, the StackGrade API fetches the site's public homepage; the result is kept briefly in memory, never stored. Graded domains are not logged. Details in the privacy policy. Page views are counted with GoatCounter (open source, no cookies, no personal data); only the page path is sent, never the domain you check.