DKIM Record Checker

Look up and validate your DKIM public key. Enter a selector, or leave it blank and we'll probe more than 40 common ones (Google, Microsoft 365, SendGrid, Mailchimp, HubSpot, Amazon SES and more).

How it works

DKIM signs each message with a private key. Receivers fetch the matching public key from DNS at <selector>._domainkey.<domain> and reject or distrust mail whose signature doesn't match.

We decode the key and report its real size. 1024-bit RSA keys still work but are below today's recommendation; anything shorter is rejected by major providers. An empty p= tag means the key was revoked.

Where do I find my selector? Open any email you sent, view the original message, and look for s= in the DKIM-Signature header.

Automate it with the API

Run this check for every address in your product, from any language.

curl -X POST "https://www.mailrambo.com/v1/verify?detail=full" \
  -H "Authorization: Bearer $MAILRAMBO_KEY" \
  -H "Content-Type: application/json" \
  -d '{"email": "jane@acme.com"}'
# -> detail.dns: { spf, dmarc_policy, dkim_selectors, bimi, ptr, mx_hosts }

API reference · Get a free API key

Frequently asked questions

What is a DKIM selector?

A label that lets one domain publish several DKIM keys, for example one per sending service. It appears in the s= tag of the DKIM-Signature header.

Should I use a 1024-bit or 2048-bit DKIM key?

2048-bit. 1024-bit keys are still accepted but considered weak; most providers now default to 2048.

Why does my DKIM record fail to decode?

Usually the key was split across TXT strings incorrectly, or characters were lost when pasting into your DNS panel. Re-copy the full value from your email provider.

Run these checks from your code

Verify addresses at signup, clean lists and read SPF/DKIM/DMARC with one API call. 100 free verifications a month, test keys that cost nothing, and the API on every plan.