Developer · Validator

DKIM key record validator.

Paste the TXT record published at a DKIM selector and check each tag against RFC 6376. The public key in p= is decoded so you can see whether it is an RSA key and how many bits long, or an ed25519 key. Runs in your browser; nothing is sent anywhere and no DNS lookup is made.

Advertisement

Input

This is the value of the TXT record at selector._domainkey.yourdomain. Surrounding quotes are fine, and a value split into several quoted strings is joined for you.

Result

Paste a record and press Validate.

The DKIM key tags this tool checks

v (recommended): if present, must be exactly DKIM1 and must be the first tag. A record that starts with any other v= value is discarded. If it is left out, DKIM1 is assumed.

p (required): the public key, base64. An empty p= means the key has been revoked and every signature using that selector fails. This tool decodes it and reads the key size.

k: key type, default rsa. ed25519 is added by RFC 8463; its p= is the 32-byte key in 44 base64 characters. Unrecognised types are ignored by verifiers.

h: colon-separated hash algorithms the key may be used with (sha1, sha256). If absent, all are allowed. RFC 8301 says SHA-1 must not be used, so h=sha256 is the tidy choice.

s: colon-separated service types, default *; email is the other defined value.

t: colon-separated flags. y means the domain is testing DKIM, so verifiers must treat failures like unsigned mail. s means signatures using i= must use exactly the d= domain, not a subdomain.

n: a note for humans; no program interprets it.

Key size: RFC 6376 section 3.3.3 says signers must use RSA keys of at least 1024 bits for long-lived keys, and RFC 8301 section 3.2 says verifiers must not accept signatures from keys under 1024 bits and must handle 1024 to 4096. The widespread advice to use 2048 bits is operational guidance, not text from either RFC.

Tag names and values are case-sensitive, a repeated tag makes the whole record invalid, and unknown tags are ignored by receivers, so this tool lists them as a note rather than an error. Whitespace around = and ; is allowed.

Sources: RFC 6376 sections 3.2, 3.3.3 and 3.6.1; RFC 8463 sections 3 and 4.2 (ed25519); RFC 8301 sections 3.1 and 3.2. Reviewed 2026-09-30.

Frequently asked questions

What is a minimal valid DKIM key record?

v=DKIM1; p= followed by the base64 public key. k=rsa is the default and can be left out.

Why does my key not fit in one TXT string?

A single TXT string holds 255 characters. A 2048-bit RSA key record is longer, so DNS providers split it into several quoted strings, which verifiers join with no whitespace. Paste the strings as they are; this tool joins them.

What does an empty p= mean?

The key is revoked. The selector is published on purpose, but every message signed with it should fail verification.

Does a valid result mean DKIM is working?

No. It only means the text follows the RFC 6376 and 8463 format and the key decodes. This tool cannot look up DNS, so it cannot tell whether the record is published at the selector, whether it matches your signing key, or whether your mail is being signed.

Syntax check only

This tool checks record format and decodes the public key only. It does not query DNS, cannot confirm the record is published, and cannot confirm the key matches the private key your mail server signs with.

Advertisement
Advertisement
Listening…