What we checkEmailEM-07
DKIM discovery
DKIM signs your mail cryptographically. We look for keys at the selectors common providers use.
- Area
- Check
- EM-07
- Included
- Free in every scan
What we check
We query a list of well-known DKIM selectors — the names Google, Microsoft, and the major sending platforms publish under.
This is a heuristic and we grade it as information only. A key at a selector we do not know about is invisible to us, and its absence here is not evidence of a problem.
Why it matters
DKIM survives forwarding, which SPF does not: a message forwarded through a mailing list keeps its signature but loses its SPF alignment.
For DMARC to be robust, you want both — either one aligning is enough to pass.
DKIM also travels with the message. A signature added by your mail provider stays valid through a forward, a mailing list, or a shared mailbox — which is why a domain relying on SPF alone sees legitimate mail fail authentication in exactly the cases where a human is least likely to suspect a technical cause.
How to fix it
- 1
Turn on DKIM signing in your mail provider's admin console; they will give you the DNS record to publish.
- 2
Do the same for every service that sends on your behalf.
Common questions
- You say DKIM is not discoverable. Is mine broken?
- Probably not. There is no way to enumerate DKIM selectors — we can only guess common ones. If your provider's console says signing is on, it is on.
- Why is this check informational?
- Because a false negative is likely and a low grade for a correctly configured domain would be wrong. It never affects your score.
- What key length should I use?
- 2048-bit. 1024 is still widely deployed and still accepted, but there is no reason to choose it for a new key.
See how your domain does on this check.
All 34 checks, a grade, and the exact fix for anything that isn’t right — in about twenty seconds, no signup.