Lookup results
How this check works
We query selector._domainkey.domain, combine TXT chunks, inspect the key tags and attempt to parse supported RSA or Ed25519 public keys.
What this check does not prove
A published key does not prove that outgoing messages are signed correctly. This checks the exact selector you provide; there is no reliable way to discover every selector from a domain alone.
Where do I find the selector?
Open the original message or source in your email app. In DKIM-Signature, s= gives the selector and d= gives the signing domain. Your email provider may also list them in its setup instructions.
Why does my provider give me a CNAME?
Some providers host the signing key for you. A CNAME at the selector name points to their key; DNS normally follows it when retrieving the TXT record.