DKIM signs outgoing mail with a private key; receivers fetch the public key from selector._domainkey.yourdomain to verify it. This tool fetches that key, follows CNAME delegation (used by Microsoft 365 and many ESPs) and reports the key size.
Table of Contents
Finding your selector
Open any message you sent and view the original headers. The DKIM-Signature header contains s= (the selector) and d= (the signing domain). cPanel uses default, Microsoft 365 uses selector1 and selector2, Google Workspace uses google, and many ESPs use s1/s2 or k1.
Keys shorter than 1024 bits are ignored by major receivers; 2048-bit RSA is the current recommendation. An empty p= means the key has been deliberately revoked.
DKIM checker at a glance



How to use this tool
- Enter the signing domain, the
d=value from the DKIM-Signature header. Usually this is the domain in the From address, for exampleexample.com. - Enter the selector (
s=value) if you know it. The tool then checks only that selector and tells you clearly when no key exists there. - Leave the selector empty to scan 23 common selectors: default, google, selector1, selector2, k1, k2, s1, s2, dkim, mail, smtp, mandrill, mxvault, zoho, zmail, protonmail, pm, mailjet, everlytickey1, x, sig1, key1 and default2. Only selectors that have a key are listed.
- Press Check DKIM. For each selector the tool reads the TXT record at
selector._domainkey.example.com; if there is none it follows a CNAME (as used by Microsoft 365 and many sending platforms) and reads the TXT record at the target.
A selector may contain letters, digits, dots, hyphens and underscores; other characters are removed. If you do not know the selector, send yourself a message and look for s= in the DKIM-Signature header, or paste the headers into the email header analyzer. Panel defaults are listed in find a DKIM selector.
How to read the results
| Field or value | What it means |
|---|---|
| Selectors found | How many selectors returned a record with a p= tag. “none of the common selectors” means the scan found nothing; it does not prove DKIM is missing, only that the selector has a less common name. |
| Selector | The selector name that was checked. |
| Green dot | A usable key: RSA 2048 bits or more, or a non-RSA key such as Ed25519. |
| Amber dot | An RSA key between 1024 and 2047 bits. It still verifies, but rotate to 2048 bits. |
| Red dot | An RSA key under 1024 bits (ignored by major receivers), an empty p= (revoked key), or, when you entered a selector, no key at that name. |
| Key: “RSA 2048-bit” | Key type from the k= tag (RSA when absent) and the size decoded from the public key. |
| Key: “RSA” without a size | The tool could not decode the public key. Check the record for a truncated value, stray quotes, spaces or a missing part after a split. |
| Key: “Key revoked (empty p=)” | The record exists but deliberately has no key, which is how a retired selector is revoked. |
| Record | The first 120 characters of the TXT record as receivers see it, with split strings already joined. |
The tags you can expect in the record are defined in RFC 6376:
| Tag | Meaning |
|---|---|
v=DKIM1 | Version. Optional, but if present it must come first. |
k= | Key type: rsa (default) or ed25519 (RFC 8463). |
p= | The public key in base64. Required; empty means revoked. |
t=y | Testing mode: receivers should not treat failures differently from unsigned mail. Remove it once signing works. |
t=s | The domain in the i= tag of signatures must match d= exactly, not a subdomain. |
h= | Hash algorithms the key may be used with, for example sha256. |
Common problems and how to fix them
“No DKIM key published at selector._domainkey.example.com”
Either the selector is wrong or the key never reached the zone the world uses. A frequent case on cPanel: the server signs mail with selector default, but the domain’s DNS is hosted on Cloudflare or at the registrar, so the key generated by cPanel only exists in the local zone. Copy the record from cPanel Email Deliverability (Manage) and add it at the real DNS host. Also check for a doubled name such as default._domainkey.example.com.example.com.
dig +short TXT default._domainkey.example.com
# Windows
nslookup -type=txt default._domainkey.example.com 1.1.1.1
The key is cut off or the size cannot be read
A 2048-bit RSA key is about 400 characters, more than the 255-character limit of one TXT string. Some DNS panels split it automatically, others truncate it or require you to enter several quoted strings. If the Key column shows “RSA” without a size, or the record ends abruptly, republish it as multiple strings with no characters added or lost. See split a 2048-bit DKIM TXT record or use the DNS TXT splitter.
Microsoft 365: DKIM cannot be enabled, status CnameMissing
Microsoft 365 only enables signing after both CNAME records exist. Create selector1._domainkey and selector2._domainkey as CNAMEs with the exact targets shown in the Defender portal; domains added from May 2025 get targets ending in dkim.mail.microsoft, older ones in onmicrosoft.com. Then enable it in the portal or with PowerShell:
Set-DkimSigningConfig -Identity example.com -Enabled $true
“body hash did not verify” in Authentication-Results
The key is fine; the message body changed after it was signed. Typical causes are disclaimers or footers added by a mail flow rule, a security gateway rewriting links, a mailing list adding a footer, or a relay re-encoding the message. Sign as the last step before mail leaves your network, or move the modification before the signing step.
“no key for signature”
The receiver looked up the selector and domain named in the signature and found no key. Compare the s= and d= values in the header with what is published, check them here with the exact selector, and allow for DNS caching if you published the key only minutes ago.
DKIM passes but DMARC still fails
The signature is valid but made with the provider’s domain, for example d= a sending platform’s own domain instead of yours. DMARC needs a passing signature whose d= matches the From domain (or its organizational domain in relaxed mode). Set up custom-domain DKIM at the provider, which usually means publishing their CNAME or TXT records under your domain. See DKIM transport signing explained.
Rotating a DKIM key without breaking mail
- Generate a new key pair under a new selector name, for example
s202610. The DKIM key generator creates a 2048-bit pair and the DNS record. - Publish the new public key and check it here with that selector. Wait at least the record’s TTL.
- Switch the mail server to sign with the new selector and confirm
dkim=passwith the news=in a test message. - Keep the old selector published for several days, so queued and delayed messages signed with it still verify.
- Revoke the old key by publishing it with an empty
p=, or delete the record.
Microsoft 365 rotates between selector1 and selector2 with Rotate-DkimSigningConfig -Identity example.com; Microsoft states the change takes four days (96 hours) to complete. To check a key size yourself, decode the p= value:
echo "MIIBIjANBgkq..." | base64 -d | openssl pkey -pubin -inform DER -text -noout | head -1
Official documentation: RFC 6376 (DKIM), DirectAdmin documentation, cPanel & WHM documentation.
Related guides: Warm up a new mail server IP or sending domain without landing in spam · Certificate lifetimes are shrinking to 47 days: what hosting providers must automate now · Choosing a VPS for a cPanel or DirectAdmin server in 2026.
Frequently asked questions
Why does the checker find no selectors?
Selectors can be any name, so a scan only finds common ones. Enter the selector from a DKIM-Signature header to check it directly.
Can I have more than one DKIM key?
Yes — each selector is independent. Most domains have one per sending service, and rotating keys means publishing a new selector before switching.
Is 1024-bit DKIM still acceptable?
It still verifies at most receivers, but 2048-bit is recommended and some providers now flag 1024-bit keys. Rotate when convenient.
What does t=y mean in a DKIM record?
It marks the key as being in testing mode, so receivers should not treat a failed signature differently from an unsigned message. Remove it once signing is confirmed to work.
Does the checker support Ed25519 DKIM keys?
Yes. A key with k=ed25519 is shown as ED25519 without a bit size and marked green. Sign with an RSA key as well, because not every receiver verifies Ed25519 signatures.
Why are the Microsoft 365 DKIM records CNAMEs?
Microsoft keeps the keys in its own DNS so it can rotate them. Your selector1 and selector2 records only point there, and the checker follows the CNAME to read the key.
What does “body hash did not verify” mean?
The message body was changed after signing, for example by a disclaimer, footer or link rewriting. The DNS key is not the problem.
Must the DKIM domain match the From address?
Not for DKIM itself, but for DMARC it must: the d= domain has to equal the From domain, or share its organizational domain when alignment is relaxed.
How long after publishing a key can I start signing?
As soon as the key is visible on public resolvers, which the checker confirms. If you queried the name before it existed, wait for the negative cache time from the SOA record.