Email signing

Free DKIM record checker.

See whether your email provider’s signing key is available. Enter your domain and the selector from its setup instructions to look up the key and find common problems.

Enter your domain and selector to see the published signing key.

  • Free to use
  • No sign-up
Your domain deserves a proper inbox.

TrekMail is email hosting for your own domain, with guided setup and a free plan to get started.

See how TrekMail works

Look up a DKIM public key

Paste a domain or website link. We’ll use the domain automatically.

Copy the key name from your email provider’s domain setup. A full DKIM DNS record name works too.

Where do I find this?

Open the DNS setup instructions from the service that sends your email. Find the DKIM record and copy its name.

For this recordselector1._domainkey.example.comEnter selector1, or paste the full record name above.

Using TrekMail? Open your domain’s setup in the dashboard and look for the DKIM record. You can also find the name after s= in a sent message’s DKIM-Signature header.

Don’t have a domain handy?

Made by TrekMail email hosting. Start with free Nano, or try an eligible paid email plan for 14 days. Explore email hosting

Email hosting by TrekMail

Your email address.
Your domain.
A proper setup.

Give your business an inbox that belongs to you. Create mailboxes on your own domain and manage them together in TrekMail.

We generate the DNS records your domain needs for receiving and sending, including SPF, DKIM and DMARC. Follow the setup guide, or publish through a supported Cloudflare connection, then check the result in your dashboard.

Free Nano plan available. No card needed to start.
Your next email addresshello@yourbusiness.com
TrekMail domain dashboard showing verified domains, mailboxes and DNS recheck controls
The TrekMail domain dashboard. Example account shown.

Bring your domainKeep your business identity.

Follow the setupGet the records and check them.

Your mail service gave you a selector. Did it publish?

Your provider gives you a DNS record and a selector, such as selector1. After you add the record, use this tool to check that the public key can be found.

What should I look for?

The expected selector has no key, an empty key, or a key format that cannot be read.

Compare the selector and DNS value with your service’s setup instructions. During key rotation, keep both old and new keys until the provider says the change is complete.

Look up the exact selector the service uses. A key can be present and well-formed while your actual messages still fail signature checks. For that, inspect a received message after the service is sending.

Check DKIM

A selector points to the right public key.

Your sending provider holds the private key. DNS publishes the public key that receiving servers use to verify signatures.

Find your selector

Open the original headers of a sent message. In DKIM-Signature, s= is the selector and d= is the signing domain. Enter those two values here. You can also find them in your provider’s DNS instructions.

Check the key, not a guessed name

The lookup uses selector._domainkey.domain. There may be several active selectors during key rotation. A missing record at one selector says nothing about the others.

Verify a real message next

A parseable public key does not prove a sender uses it correctly. Read Authentication-Results in a received message to confirm DKIM and DMARC alignment.

A little knowledge. A better setup.

How to find your DKIM selector and check the key

A DKIM lookup needs two things: the signing domain and the selector your sending service uses.

Check DKIM

Find the selector in a sent message

Open the original headers of a message delivered by your sending service. Look for DKIM-Signature. The s= value names the selector, while d= names the signing domain. In the example below, enter example.com as the domain and selector1 as the selector.

You can also find the selector in your provider’s domain setup screen. Google Workspace, Microsoft 365 and other services may use different or custom selectors. Use the value for your account rather than guessing a common name.

What it looks like · example
DKIM-Signature: ... d=example.com; s=selector1; ...

Lookup name: selector1._domainkey.example.com

Illustrative header excerpt; it is not a complete signature or a key to publish.

Read the public key record

The DKIM checker looks at selector._domainkey.domain. Depending on the provider, your DNS may contain the public key directly or a CNAME that points to a provider-managed record. The report inspects the available key and highlights common format problems or a revoked key with an empty p= value.

Check real messages after publishing

DKIM stands for DomainKeys Identified Mail. Its private key stays with the sender; the public key helps receivers check a message’s signature. A key appearing in DNS does not prove that the service signs messages correctly or that DKIM aligns with the visible From address.

After the record is published, send a test message through the service and inspect Authentication-Results in the received copy. If you are rotating keys, follow the provider’s overlap instructions so messages signed with the previous key can still be verified.

Read the DKIM specification

Understand the result. Take the next step.

Practical guides from TrekMail, with setup instructions and deeper explanations for this tool.

Start free. Give your email room to grow.

Choose a free inbox to get started, or a paid plan for sending through TrekMail. One plan covers your account, with no per-seat fees.

Free for now

Nano

$0/month

Your own domain, your first mailboxes, no credit card.

  • 10 domains
  • 10 mailboxes per domain
  • 5 GB shared storage
  • Receive email and use webmail

Sending through TrekMail is included in paid plans. Nano can use your own SMTP service.

Send and receive with TrekMail.

Try an eligible paid email plan for 14 days.

Starter

For a small business

$4/month

  • 50 domains
  • 100 mailboxes per domain
  • 15 GB shared storage
  • Sending included

Pro

For a growing team

$10/month

  • 100 domains
  • 300 mailboxes per domain
  • 50 GB shared storage
  • Sending included

Agency

For client domains

$29/month

  • 1000 domains
  • 1000 mailboxes per domain
  • 200 GB shared storage
  • Sending included
Compare plans & start a trial

USD prices, billed monthly. Annual options available. Trials require a card and convert to the selected paid plan on the date shown at checkout. Cancel before that date to avoid a charge.

More from TrekMail

An inbox is just the beginning.

Read your business email in TrekMail webmail, or connect your favorite email app. Explore the other products when you need more from your workspace.

Explore email hosting
TrekMail webmail inbox with mail folders, messages, calendar and contacts
TrekMail webmail. Example inbox shown.

Good questions. Clear answers.

Questions about DKIM keys

Find the details you need, then return to the tool when you’re ready.

Check DKIM
Where do I find a Google or Microsoft selector?

Use your administrator’s DNS instructions or the s= tag in a message sent by that service. Provider defaults can vary, and selectors can change during rotation.

What does an empty p tag mean?

An empty p= value revokes the key at that selector. It is not a usable public key for verifying signatures.

What key length should I use?

For RSA, current DKIM guidance requires at least 1024 bits and recommends 2048 bits. This tool flags RSA keys below 2048 bits. Ed25519 uses a different key format and size.

Can this verify a DKIM signature?

This checks the DNS key only. Cryptographic signature verification also needs the original message headers and body.

What if the DKIM record is not found?

Confirm the signing domain and selector with your provider, check that the record was added to the correct DNS zone, and allow cached answers to expire. A missing key at one selector does not mean that the domain has no other DKIM keys.

Is a DKIM selector the same as a public key?

No. The selector is the name used to find a key in DNS. The public key is the value published at that lookup name or its provider-managed destination.

Put your name on your email.

Create your TrekMail account, bring your domain and follow the setup. Start with free Nano, or try an eligible paid email plan for 14 days.

Compare hosting plans
Nano needs no card. Paid trials require a card.

Sign in to TrekMail

Access your dashboard, mailboxes and DNS.

12 characters passwords match

Reset email sent

If an account exists for this email, we've sent password reset instructions.

By continuing, you agree to TrekMail's Terms and Privacy Policy.