To check DKIM status, query the selector’s public key in DNS (s=selector under the DKIM d= signing domain) or run a free DKIM checker. A valid record returns a public key; failures usually mean the selector is missing, the key is wrong, or the signed message was changed. DMARC alignment is a separate check and can fail even when DKIM passes.
DKIM (DomainKeys Identified Mail) lets receiving servers verify that a message was authorized by the domain and was not altered in transit. When it fails, inbox placement suffers—especially for bulk or transactional volume under Gmail and Yahoo requirements.
What a healthy DKIM record looks like
A published DKIM record is a TXT record at selector._domainkey.signing-domain.example. The value typically starts with v=DKIM1; k=rsa; p= followed by the public key. Common selectors include default, google, selector1, or provider-specific names such as those issued by ArawaMail.
- Selector – the left-hand label that identifies which key pair signed the message.
- Public key – the
p=value that receivers use to validate the signature. - Key type – almost always RSA; some providers now support Ed25519.
ArawaMail publishes the exact selector and record shape when you enable sending for a domain. See the ArawaMail DNS Records reference for the canonical format.
How to check DKIM status in under a minute
- Identify the selector used by the sending system (headers show
s=selectorinside the DKIM-Signature). - Look up
selector._domainkey.yourdomain.comwith dig, nslookup, or a free tool. - Follow a provider CNAME if present and confirm the resolved TXT key has a non-empty
p=value. Use thed=domain ands=selector from the signature, not a guessed selector under the visible From domain. - Send a test message and inspect the Authentication-Results header for
dkim=pass.
The fastest path for most operators is the free DKIM Checker on the ArawaMail tools page. Enter the domain and selector; the tool returns the published key or a clear failure reason.
Common DKIM failures and how to diagnose them
| Symptom | Likely cause | Fix |
|---|---|---|
| No TXT record found | Selector never published or wrong name | Confirm the exact selector from the provider dashboard and publish the TXT |
| Empty or truncated p= value | DNS provider length limit or copy-paste error | Re-publish the full key; some providers require multiple strings |
| dkim=fail in headers | Message body or headers altered after signing, or wrong private key | Check for intermediate relays that rewrite content; rotate keys if compromised |
| dkim=pass but DMARC fails | Signature domain does not align with From domain | Under relaxed alignment, compare organizational domains; under strict alignment, the domains must match exactly; see DMARC Alignment vs SPF Pass |
| Intermittent failures after rotation | Old selector removed before TTL expires | Keep the old key available long enough for messages already signed with it to finish delivery, as well as DNS caches to expire; follow DKIM Key Rotation |
How we analyze DKIM problems
We start from the Authentication-Results and DKIM-Signature headers on a real delivered (or rejected) message, extract the selector and domain, query live DNS, then compare the published public key against the signature validation result. This sequence isolates DNS publication errors from signing-configuration or relay-rewrite problems without relying on third-party scorecards alone.
When to re-check after changes
- Immediately after publishing a new selector.
- After any key rotation (keep old selectors through the provider’s recommended overlap, covering queued signed mail and DNS caches).
- When Gmail or Yahoo starts reporting authentication failures in postmaster tools.
- Before major volume increases or Black Friday campaigns.
For the broader authentication picture, combine the DKIM check with the SPF and DMARC tools on the same tools page and review the SPF, DKIM, and DMARC explained guide.
FAQ
What is a DKIM selector?
The selector is the unique name that points to a specific public key in DNS. Receivers look up selector._domainkey.domain to obtain the key that validates the signature.
Can I check DKIM without sending an email?
Yes. A DNS lookup of the selector record tells you whether the public key is published. Full end-to-end validation still requires a signed message.
Why does DKIM pass but mail still goes to spam?
DKIM is only one signal. Content quality, domain reputation, engagement history, and list hygiene also matter. See Why your emails go to spam.
How often should I rotate DKIM keys?
Use your provider’s supported rotation mechanism and security policy. Rotate promptly if the private key is exposed; a staffing change alone is not proof of key compromise. Always publish the new selector first and keep the old one through a delivery-and-cache overlap based on provider guidance.
Sources and review
Documentation reviewed on 3 October 2026. Examples are illustrative and must be adapted to your application.