DKIM record checker
DKIM (DomainKeys Identified Mail) adds a cryptographic signature proving your message was not altered and tying it to your domain.
Checker output
DKIM
selector._domainkey CNAME valid
At a glance
Plain-language summary for buyers, operators, and search engines.
In simple terms
A DKIM checker validates that your selector publishes a public key in DNS and that signing aligns with your From domain.
Why it matters
DKIM failures break DMARC alignment and reduce trust with mailbox providers.
How CloudJet handles it
Verify selector CNAME/TXT records, key length, and signing coverage across your mail streams.
Run the Dkim Checker
See the actual published DNS records, validation results, and suggested fixes — free, no signup.
Live checker
Queries public DNS — shows the actual published records and any issues found.
Enter a domain to see the published DNS record, validation results, and suggested fixes.
Real DNS lookups
We query public DNS and show the exact TXT/MX records published for your domain.
Records + issues
Each check shows the live record, what passed, what failed, and how to fix it.
Go deeper in CloudJet
Sign up to save history, monitor domains, and automate remediation.
How to use this checker
01
Enter your domain above and click Run check for a live DNS lookup — free, no account required.
02
Sign up for CloudJet to save history, monitor changes, and automate remediation across your sending domains.
What DKIM checks cover
01
DKIM uses a selector (e.g. selector1._domainkey.yourdomain.com) publishing a public key.
02
The sending server signs headers and body; receivers verify with the DNS-published key.
Common DKIM failures
Wrong selector after ESP or provider migration.
Expired or rotated keys not updated in DNS.
Partial MIME signing across multipart messages.
From domain mismatch relative to the signing domain.
Related pages
Continue exploring capabilities that connect to this topic.
Questions & answers
How to run this check, read results, and pair with CloudJet monitoring.
Yes for most modern programs. Many providers expect both SPF and DKIM, and DMARC policies often require alignment on at least one.
Rotate on provider changes, security incidents, or per your security policy. Always update DNS before switching signing keys in production.
Monitor these checks in CloudJet
Free checks run on this page. Sign up for saved history, alerts, and continuous domain monitoring.