Website diagnostics
DKIM Check & Test
Run a free DKIM check and test online with Web Health. Verify DKIM DNS TXT records, public keys, selector configuration, and email authentication settings for any domain.
Understanding DKIM Signature Verification
DomainKeys Identified Mail (DKIM) ensures that email messages are not tampered with during transmission between sending and receiving servers. Testing your DKIM selector and public key record protects your email sender domain reputation.
Key DKIM Record Parameters
- v=DKIM1: Required protocol version tag.
- k=rsa: Key algorithm specification (RSA or Ed25519).
- p=...: Base64-encoded public key string.
- Selector Hostname: DNS location tag (selector._domainkey.domain.com).
- Key Bit-Length: RSA key size (recommended: 2048-bit).
DKIM Management Best Practices
- Use 2048-bit RSA Keys: Upgrade legacy 1024-bit keys to 2048-bit RSA keys.
- Unique Selectors per Service: Assign distinct selectors for Google, Office 365, Mailchimp.
- Rotate Key Pairs Annually: Periodically publish fresh DKIM public keys in DNS.
- Align with DMARC: Ensure the DKIM signing domain matches the From: header domain.
Frequently Asked Questions
DKIM (DomainKeys Identified Mail) is an email authentication method that attaches a cryptographic digital signature to outgoing email headers. Receiving mail servers use the domain's public DKIM key published in DNS to verify message authenticity and integrity.
