⚠ Message signing

DKIM Checker

Check whether your domain publishes DKIM keys on common selectors. DKIM cryptographically signs your outgoing mail so receivers can verify it was not altered and really came from you.

check ▸

What DKIM does

DKIM (DomainKeys Identified Mail) publishes a public key in DNS at <selector>._domainkey.yourdomain.com. Your mail server signs each message with the matching private key; receivers fetch the public key to verify the signature.

Why selectors matter

DKIM keys live under a selector name chosen by your mail provider — for example google, selector1 or s1. There is no way to enumerate every selector, so Nattvakt probes the most common ones.

A "not detected" result does not always mean DKIM is missing — your provider may use a custom selector. Check the selector name in your mail admin console.

Getting DKIM right

Enable DKIM in your mail provider's admin console, publish the DNS record they give you, and confirm with a test message. Rotate keys periodically and remove retired selectors.

Frequently asked questions

What is a DKIM selector?

A label (such as google or selector1) that identifies which DKIM public key to look up at selector._domainkey.<domain>.

Why does the checker say DKIM is not detected?

It probes common selectors only. If your provider uses a custom selector, DKIM may still be active — check the selector name in your mail admin console.

Does DKIM stop spoofing on its own?

No. DKIM proves a message was not altered and is paired with DMARC to enforce a policy. Use SPF, DKIM and DMARC together.

// Other free checks
DMARC Checker
Email spoofing protection
SPF Checker
Sender authorization
DNSSEC Checker
DNS integrity
SSL Certificate Checker
Certificate & HTTPS
Security Headers Checker
HTTP response headers
DNS Checker
DNS records lookup