DNS & Deliverability

How to Check DKIM Status and Diagnose Failures

Check DKIM status with a DNS lookup or free checker, then diagnose missing selectors, wrong keys, and alignment failures that break deliverability.

Published

Published by Arawa Mail.

How to Check DKIM Status and Diagnose Failures

To check DKIM status, query the selector’s public key in DNS (s=selector under the DKIM d= signing domain) or run a free DKIM checker. A valid record returns a public key; failures usually mean the selector is missing, the key is wrong, or the signed message was changed. DMARC alignment is a separate check and can fail even when DKIM passes.

DKIM (DomainKeys Identified Mail) lets receiving servers verify that a message was authorized by the domain and was not altered in transit. When it fails, inbox placement suffers—especially for bulk or transactional volume under Gmail and Yahoo requirements.

What a healthy DKIM record looks like

A published DKIM record is a TXT record at selector._domainkey.signing-domain.example. The value typically starts with v=DKIM1; k=rsa; p= followed by the public key. Common selectors include default, google, selector1, or provider-specific names such as those issued by ArawaMail.

  • Selector – the left-hand label that identifies which key pair signed the message.
  • Public key – the p= value that receivers use to validate the signature.
  • Key type – almost always RSA; some providers now support Ed25519.

ArawaMail publishes the exact selector and record shape when you enable sending for a domain. See the ArawaMail DNS Records reference for the canonical format.

How to check DKIM status in under a minute

  1. Identify the selector used by the sending system (headers show s=selector inside the DKIM-Signature).
  2. Look up selector._domainkey.yourdomain.com with dig, nslookup, or a free tool.
  3. Follow a provider CNAME if present and confirm the resolved TXT key has a non-empty p= value. Use the d= domain and s= selector from the signature, not a guessed selector under the visible From domain.
  4. Send a test message and inspect the Authentication-Results header for dkim=pass.

The fastest path for most operators is the free DKIM Checker on the ArawaMail tools page. Enter the domain and selector; the tool returns the published key or a clear failure reason.

Common DKIM failures and how to diagnose them

SymptomLikely causeFix
No TXT record foundSelector never published or wrong nameConfirm the exact selector from the provider dashboard and publish the TXT
Empty or truncated p= valueDNS provider length limit or copy-paste errorRe-publish the full key; some providers require multiple strings
dkim=fail in headersMessage body or headers altered after signing, or wrong private keyCheck for intermediate relays that rewrite content; rotate keys if compromised
dkim=pass but DMARC failsSignature domain does not align with From domainUnder relaxed alignment, compare organizational domains; under strict alignment, the domains must match exactly; see DMARC Alignment vs SPF Pass
Intermittent failures after rotationOld selector removed before TTL expiresKeep the old key available long enough for messages already signed with it to finish delivery, as well as DNS caches to expire; follow DKIM Key Rotation

How we analyze DKIM problems

We start from the Authentication-Results and DKIM-Signature headers on a real delivered (or rejected) message, extract the selector and domain, query live DNS, then compare the published public key against the signature validation result. This sequence isolates DNS publication errors from signing-configuration or relay-rewrite problems without relying on third-party scorecards alone.

When to re-check after changes

  • Immediately after publishing a new selector.
  • After any key rotation (keep old selectors through the provider’s recommended overlap, covering queued signed mail and DNS caches).
  • When Gmail or Yahoo starts reporting authentication failures in postmaster tools.
  • Before major volume increases or Black Friday campaigns.

For the broader authentication picture, combine the DKIM check with the SPF and DMARC tools on the same tools page and review the SPF, DKIM, and DMARC explained guide.

FAQ

What is a DKIM selector?

The selector is the unique name that points to a specific public key in DNS. Receivers look up selector._domainkey.domain to obtain the key that validates the signature.

Can I check DKIM without sending an email?

Yes. A DNS lookup of the selector record tells you whether the public key is published. Full end-to-end validation still requires a signed message.

Why does DKIM pass but mail still goes to spam?

DKIM is only one signal. Content quality, domain reputation, engagement history, and list hygiene also matter. See Why your emails go to spam.

How often should I rotate DKIM keys?

Use your provider’s supported rotation mechanism and security policy. Rotate promptly if the private key is exposed; a staffing change alone is not proof of key compromise. Always publish the new selector first and keep the old one through a delivery-and-cache overlap based on provider guidance.

Sources and review

Documentation reviewed on 3 October 2026. Examples are illustrative and must be adapted to your application.

Simple, transparent plans

Start free. Grow when your email does.

Get one domain, API access and 3,000 transactional emails every month at no cost.

Compare plans