RFC 6376• Free Instant Diagnostic

DKIM Key Checker & Selector Prober

Probe over 45 industry-standard DKIM selectors, inspect public RSA/Ed25519 cryptographic keys, and confirm cryptographic strength.

DKIM Key Checker
Guest:
3/3 left
Try sample:
Inspection Workflow

How DKIM Key Checker Works

STEP 01

Selector Probing

Constructs FQDN queries `<selector>._domainkey.<domain>` for known and custom selectors.

STEP 02

Cryptographic Key Extraction

Decodes Base64 public key data to determine RSA/Ed25519 algorithms.

STEP 03

Bit Strength Evaluation

Checks if key length meets the modern RFC 8301 minimum requirement of 2048 bits.

Specification Compliance

RFC Engineering Standards

Every check performed by this tool adheres strictly to the Internet Engineering Task Force (IETF) Request for Comments:

  • RFC 6376 (DomainKeys Identified Mail)
  • RFC 8301 (Cryptographic Key Sizes)
Diagnostic Remediation

Common Issues & How to Fix Them

If our diagnostic discovers configuration anomalies, use the remediation steps below:

1024-Bit RSA Key DetectedWEAK_KEY_SIZE

Remediation: 1024-bit RSA keys are deprecated by modern mail receivers. Upgrade to a 2048-bit key in your email provider's console.

Empty Public Key Tag (p=)REVOKED_DKIM_KEY

Remediation: An empty `p=` tag indicates a revoked key. Any emails signed with this selector will fail validation.

Knowledge Base

Frequently Asked Questions

What is a DKIM selector?

A selector is an identifier that points to a specific DKIM public key in DNS. It allows a domain to use multiple sending services (e.g. Google Workspace, SendGrid, Zendesk) simultaneously without key conflicts.

Why should I use 2048-bit keys instead of 1024-bit?

Advances in computing power have made 1024-bit RSA keys vulnerable to factorization. Major providers (including Google and Microsoft) recommend or enforce 2048-bit keys for sender authority.

Deliverability Suite

Explore Other Free Diagnostic Tools

View All 7 Tools
Beyond DNS Diagnostics

Verify Real Mailbox Existence in Real-Time

DNS tests only tell you if a server is reachable. BounceLayer's API connects directly to recipient mail servers via port 25 SMTP handshakes to confirm exact mailbox existence in under 140ms.