DKIM record checker
Enter a domain and a selector to look up the DKIM public key, check it's valid, and see its size.
Finding the selector
The selector is the part before ._domainkey in the DNS record your email provider gave you. toSend uses tosend. Google Workspace uses google by default, Microsoft 365 uses selector1 and selector2, SendGrid uses s1 and s2, and Resend uses resend. You can also find it in the s= value of the DKIM-Signature header on an email you've received.
DKIM and toSend
Every domain added to toSend gets a DKIM key published at tosend._domainkey, and every email is signed with it. New domains get a key unique to your team, so DNS records left behind by a removed domain can't be used to verify it in another account.
Questions
What does an empty p= mean?
The key has been revoked. Mail signed with that selector fails DKIM. If you still send with it, publish the current key from your provider.
Is a 1024-bit key good enough?
Yes. All major mailbox providers accept 1024-bit RSA keys. 2048-bit is stronger but doesn't fit in a single DNS string, so some DNS hosts handle it badly. Keys under 1024 bits are rejected.
Why does the record show as a CNAME?
Some providers ask you to publish a CNAME that points to a key they host, so they can rotate it for you. The checker follows the CNAME and checks the key at the other end.
Ready to send? Your first 10,000 are on us.
Every feature included. No tiers. For one website, one app, or fifty client sites.