Skip to content
Hivex tools · EmailFree · No account

DKIM checker, with selector discovery.

Finds a domain's DKIM signing keys by trying the selectors common senders use, then checks each key's type and size.

How DKIM works.

The sending server signs each message with a private key. The matching public key sits in DNS at selector._domainkey.example.com, and receivers use it to check that the message really comes from the domain and was not changed on the way.

Finding the selector.

A domain can have many keys, one per selector. The selector a message used is the s= value in its DKIM-Signature header. Without it, this page tries the selectors common services use (google for Google Workspace, selector1 and selector2 for Microsoft 365, k1 for Mailchimp, s1 and s2 for SendGrid and others). A key it does not find may still exist under another selector: type selector._domainkey.example.com to check it directly.

Key size and state.

  • RSA keys need at least 1024 bits, and receivers must reject anything shorter. 2048 bits is the recommended size.
  • An empty key (p=) means the key was revoked: mail signed with it fails.
  • t=y marks a key in testing: receivers should not treat failures differently from unsigned mail.

Questions people ask.

What is DKIM?

A signature on outgoing mail, checked against a public key published in DNS, that proves the message comes from the domain and was not changed.

How do I find my DKIM selector?

Open a message you sent, view its headers and find s= in the DKIM-Signature header. That value is the selector.

What DKIM key length should I use?

2048-bit RSA. Receivers must reject keys shorter than 1024 bits.

Why does the checker find no DKIM key?

The domain may sign with a selector this tool does not try. Look up selector._domainkey.yourdomain with the selector from a message header.

Hivex index

Short names, still free to register.

Starting something new? Hivex keeps a live index of short, brandable .si names nobody has claimed yet, each checked with the registry.

Browse free names

From code, or an AI assistant.

Hivex's free JSON API and MCP server check domains, DNS and registration records from your own code or from AI assistants that speak MCP. No key needed.

The API guideThe MCP serverOpenAPI schema

Sources

  1. RFC 6376: DomainKeys Identified Mail (DKIM) signatures
  2. RFC 8301: Cryptographic algorithm and key usage update to DKIM
  3. RFC 8463: A new cryptographic signature method for DKIM (Ed25519)

By Hivex. Updated 10 October 2026. Lookups run live through Cloudflare's public resolver and are kept for at most five minutes.