Record presence
Whether the specified selector has a reachable DKIM DNS record.
Free email security tool
Check whether a domain publishes a DKIM record for a specific selector and identify missing or invalid configuration.
DKIM records are selector-specific. Enter the domain and selector used by your email provider to check the corresponding DNS record.
DKIM uses a selector-specific public DNS record to help receiving email systems evaluate a signed message. The DNS record is one part of email authentication, alongside SPF and DMARC.
A selector identifies the DKIM record your email provider uses. The same domain can have more than one selector, especially while keys are rotated.
Whether the specified selector has a reachable DKIM DNS record.
Whether the record can be safely interpreted as a DKIM key record.
Whether the key is present, revoked, missing or uses a recognized type.
CloudSpex checks the DKIM DNS record for the domain and selector you provide. It does not automatically discover every selector or verify a DKIM signature from an email message.
Check your email provider setup documentation or DNS configuration. A sent message’s Authentication-Results or DKIM-Signature header can also identify the selector; do not upload email messages here.
Common issues include a wrong selector, a missing DNS record, malformed configuration, a missing or revoked public key, and DNS propagation or availability problems.
Checks one selector-specific DKIM DNS record.
Reviews SPF, DKIM and DMARC together as a broader public summary.
Shows the current public DNS result for the selector you enter.
Helps detect DKIM, SPF and DMARC configuration changes after provider, DNS or key-rotation work.
A DKIM record is a public DNS record that contains the public key information used with DKIM email signing for a specific selector.
A DKIM selector is the label chosen by an email provider or administrator to identify one DKIM record, such as google._domainkey.example.com.
CloudSpex checks the DKIM DNS record for the domain and selector you provide and reports whether the record can be safely interpreted.
Check your email provider setup instructions, DNS configuration, or the Authentication-Results or DKIM-Signature header of a sent message. Do not upload email messages to this checker.
A missing record can prevent receivers from finding the public key for that selector. Verify the selector and publish the expected DKIM record before checking again.
Yes. A domain can use multiple selectors, for example during key rotation. This checker evaluates only the single selector you enter.
No. This checker validates the DNS record for the selector you provide. It does not verify the DKIM signature of an email message.
No. CloudSpex reads the public DKIM DNS record only and does not change DNS, email settings or domain configuration.
Add your domain to CloudSpex to monitor DKIM, SPF, DMARC and related email-security configuration changes.
Start Monitoring FreeCheck Another Selector