DKIM inspector
Selector key checkRetrieve one DKIM selector, decode its public key, and inspect key strength, test flags, hash restrictions, and service scope.
Enter a domain and selectorThe result distinguishes missing, revoked, malformed, legacy-strength, test-mode, and resolver-failure states.
Selectors and key strength
DKIM selectors are chosen by senders and are not published in an enumerable index, so this tool checks only the selector you supply. Find it in a message's DKIM-Signature s= value or in your mail provider's setup instructions.
RSA keys below 1024 bits are rejected; 1024-bit keys are identified as legacy, while 2048 bits or stronger is recommended. Ed25519 keys must decode to exactly 32 bytes. This checks the DNS key record, not a message signature.