DKIM record checker
Look up a domain's DKIM key for a given selector and check that it is published correctly.
- Key presence, type and length
- Revoked and malformed keys flagged
- Your selector, or the common ones tried for you
Give it something to look up — Glee will do the digging.
How the dkim checker works
DKIM signs each outgoing message with a private key; receivers verify the signature with a public key published in DNS under a selector name, at <selector>._domainkey.<domain>. A domain can have many selectors — one per sending service — and there is no way to list them from DNS.
Enter the domain and, if you know it, the selector (it appears as s= in the DKIM-Signature header of any message the domain sends); without one we try the selectors the common mail services use. We fetch the record and report whether a key is published, its algorithm and length, and problems such as a revoked (empty) key, a key too short to be trusted, or syntax that receivers will reject.
What each field means
- Key
- Present, revoked or missing for this selector.
- Key length
- 1024 bits is the minimum; 2048 is recommended.
Where this check stops
- A selector is required: no record for one selector cannot prove the domain has no DKIM.
The same check, through the API
Same calculation, same answer, with a key. 3 credits per check ($0.30 per 1,000). A free account includes 1,000 credits a month.
GET /v1/email-auth/acme.com?selector=s1 Host: gleanzy.com Authorization: Bearer $GLEANZY_KEY
Frequently asked
Where do I find the selector?
In a message's headers: DKIM-Signature: … s=selector; d=domain.