DKIM checker
Check DKIM keys for your domain, with or without knowing the selector.
DKIM signs outgoing mail with a private key; receivers fetch the public key from selector._domainkey.yourdomain to verify the signature. Without a valid DKIM signature from your own domain, DMARC can only pass through SPF, which breaks on forwarding.
MailVakt detects your mail providers and probes their known selectors first, then a wider dictionary. It reports missing, revoked, weak (under 1024-bit) and testing-mode keys. If you know your selector, enter it below.
Questions
- Where do I find my DKIM selector?
- Open a message you sent, view the original headers, and look for s= in the DKIM-Signature header. Your email provider’s DKIM settings page shows it too.
- Is a 1024-bit DKIM key still OK?
- It is accepted, but 2048-bit keys are recommended. Keys under 1024 bits are rejected by major receivers.
Fix this from ChatGPT or Claude
MailVakt is an MCP server, so your assistant can run this check itself, read the findings and walk you through the DNS edit. Ask it:
“Find the DKIM selectors published for example.com, check the key size, and tell me if any are missing or in testing mode.”
- Claude: Settings → Connectors → Add custom connector, then paste
https://mcp.mailvakt.com/mcp. - Cursor and other MCP clients: add the same address as an MCP server. Setup details.
Checks are free and need no account. Sign in only to collect DMARC reports for a domain.