DKIM checker

Check DKIM keys for your domain, with or without knowing the selector.

Just the part after the @. Free, no sign-up, and the result gets a shareable link.

DKIM signs outgoing mail with a private key; receivers fetch the public key from selector._domainkey.yourdomain to verify the signature. Without a valid DKIM signature from your own domain, DMARC can only pass through SPF, which breaks on forwarding.

MailVakt detects your mail providers and probes their known selectors first, then a wider dictionary. It reports missing, revoked, weak (under 1024-bit) and testing-mode keys. If you know your selector, enter it below.

Questions

Where do I find my DKIM selector?
Open a message you sent, view the original headers, and look for s= in the DKIM-Signature header. Your email provider’s DKIM settings page shows it too.
Is a 1024-bit DKIM key still OK?
It is accepted, but 2048-bit keys are recommended. Keys under 1024 bits are rejected by major receivers.

Fix this from ChatGPT or Claude

MailVakt is an MCP server, so your assistant can run this check itself, read the findings and walk you through the DNS edit. Ask it:

“Find the DKIM selectors published for example.com, check the key size, and tell me if any are missing or in testing mode.”
  • Claude: Settings → Connectors → Add custom connector, then paste https://mcp.mailvakt.com/mcp.
  • Cursor and other MCP clients: add the same address as an MCP server. Setup details.

Checks are free and need no account. Sign in only to collect DMARC reports for a domain.