Look up a domain's DKIM key by selector and confirm it is published correctly.
Enter a domain to check its DKIM configuration.
DKIM (DomainKeys Identified Mail) adds a cryptographic signature to your outgoing email. Receiving servers fetch your public key from DNS to verify the message was not altered and genuinely came from your domain.
DKIM keys are published under a selector, such as google._domainkey.example.com. This checker fetches the key for whatever selector you enter and confirms it is present and a healthy size.
A selector is a label that lets a domain publish multiple DKIM keys, for example one per email provider. The DNS name is selector._domainkey.example.com. Your provider tells you which selector it uses (common ones include google, s1, k1, selector1).
Check your email provider's DKIM setup page, or inspect the DKIM-Signature header of an email you sent, where the s= tag is the selector. Enter that selector here along with your domain.
2048-bit RSA keys are the current recommendation. 1024-bit keys still work but are weaker. If this checker flags a short key, ask your provider to rotate to a 2048-bit key.
Every one runs a real check, live, with nothing to install.
A one-off check is useful, but PulseStack repeats it every minute and alerts you the moment something changes. Start free with 5 monitors, no card required.