Email Security
DKIM Selector Scanner & Public Key Inspector
Scan and verify DomainKeys Identified Mail (DKIM) TXT records per RFC 6376. DKIM adds a cryptographic signature to every outgoing email, allowing receiving mail servers to verify that the message was not tampered with in transit and was genuinely sent by an authorized server. Automatically probe 30+ popular email service provider selectors (Google Workspace, Microsoft 365, Amazon SES, SendGrid, Mailchimp) and verify RSA key bit length and validity.
Key Capabilities & Features
dnsfyi combines high-speed global Anycast DNS queries with comprehensive security auditing into a unified diagnostic suite.
- • Auto-probing across top 30+ industry ESP DKIM selectors
- • RSA key length verification (1024-bit legacy vs 2048-bit modern standard)
- • Public key syntax validation and base64 ASN.1 key extraction
- • Direct TXT record DNS status confirmation across multiple resolvers
- • Ed25519 elliptic curve key support detection
- • Key revocation detection (p= empty value)
How to Use This Tool
To audit any domain or IP address, enter the hostname into the search box to run an instant parallel multi-resolver inspection.
- Enter your domain name. dnsfyi automatically probes common DKIM selectors used by Google, Microsoft, SendGrid, and other ESPs.
- Or manually enter a known selector name (e.g., 'google', 'selector1', 'k1') to look up a specific DKIM record.
- Review the public key details: key type (RSA or Ed25519), bit length (1024 or 2048), and validity status.
- A 1024-bit key is considered weak — plan to rotate to 2048-bit.
- An empty p= value means the key has been revoked and DKIM signing will fail for all messages.
Common Use Cases
dnsfyi is primarily used to troubleshoot email deliverability failures, verify global DNS propagation, and audit SSL certificate health.
- → Verifying DKIM is correctly published after configuring a new email service provider.
- → Checking if the DKIM public key matches what your ESP is using to sign outgoing emails.
- → Auditing DKIM key strength — 1024-bit RSA keys should be rotated to 2048-bit.
- → Diagnosing DKIM failures reported in DMARC aggregate reports.
- → Confirming DKIM selector rotation after a security incident.
Frequently Asked Questions
Find direct answers about dnsfyi's multi-resolver query engine, privacy policy, domain security checks, and free REST API.
- What is a DKIM selector?
- A DKIM selector is a string label that allows a domain to publish multiple DKIM public keys. The selector is specified in the email's DKIM-Signature header (s= tag). For example, s=google means the public key is at google._domainkey.yourdomain.com.
- Why is my DKIM record not found?
- Common reasons: (1) The selector name is wrong — ask your ESP for the exact selector. (2) The TXT record hasn't propagated yet — DNS changes can take up to 48 hours. (3) The record was published at the wrong DNS location — it must be at {selector}._domainkey.{domain}.
- What is the difference between 1024-bit and 2048-bit DKIM keys?
- A 2048-bit RSA key provides significantly stronger cryptographic security than a 1024-bit key. 1024-bit keys are considered weak by modern standards and NIST recommends phasing them out. Most major ESPs now default to 2048-bit. Rotate your DKIM keys annually.
- Can I have multiple DKIM keys for one domain?
- Yes. You can have multiple DKIM selectors (and thus multiple public keys) for one domain — this is actually recommended. Use different selectors for different sending services (e.g., 'google' for Google Workspace, 'sendgrid' for SendGrid), and rotate them regularly.
- Does DKIM prevent email spoofing by itself?
- DKIM proves message integrity and authenticates the signing domain, but without DMARC, it doesn't prevent From: header spoofing. A spoofer can sign with their own domain's DKIM key while spoofing your From: address. DMARC enforces alignment between the DKIM d= domain and the From: header.