Email & SMTP
Check DKIM Configuration
Verify your DKIM setup is actually signing outgoing mail, not just present in DNS.
The Problem
A DKIM record can exist in DNS and still not be doing anything, because your mail server isn't configured to sign with it or the selector doesn't match — and most people never find out until a provider starts rejecting their mail.
About this problem
A DKIM record existing in DNS tells you nothing about whether mail is actually being signed with it — the selector has to match exactly what the mail server or sending platform is using, and the private key has to correspond to the public key published in DNS, or signing silently fails.
This mismatch is common after switching email providers, migrating mail servers, or when DKIM was set up once years ago and nobody has verified since that it still lines up with the current sending setup.
What's Included
- Checking the DKIM DNS record (selector and public key) is published correctly
- Sending test mail and confirming the DKIM signature actually validates
- Checking the signing configuration on your mail server or provider side
- A clear yes/no on whether DKIM is genuinely working, with the cause if not
What's NOT Included
- Fixing a broken configuration (see "Fix DKIM Configuration")
- Setting up DKIM on a platform I don't have access to configure
- Key rotation policy or long-term key management
How It Works
- Look up the DKIM selector record in DNS and confirm it publishes a valid public key.
- Send a real test email and inspect the DKIM-Signature header to see which selector and domain it actually used.
- Verify the signature cryptographically validates against the published public key.
- Check the sending platform or mail server's own DKIM signing configuration for mismatches.
- Give a clear pass/fail verdict with the specific point of failure if it's not working.
In practice: you buy the service, send over whatever access or details the job needs, I investigate and do the work, and you confirm it's resolved before we call it done.
Frequently Asked Questions
- How do I know if DKIM is actually working?
- The only reliable way is to send a real test email and check the DKIM-Signature header in the received message, then verify it validates — a DNS record existing on its own doesn't confirm signing is active.
- Why does my DKIM record show up but emails still fail DKIM checks?
- The most common cause is a selector mismatch — the mail server is signing with a selector that doesn't match what's published in DNS, so the receiving server can't find the right public key to verify against.
- What is a DKIM selector?
- It's a label (like 'default' or 'google') that lets a domain publish multiple DKIM keys at once — the signing mail server specifies which selector it used, so the receiver knows which DNS record to check.
- Can I have DKIM working for one email tool but not another?
- Yes — if you send from multiple platforms (your main inbox, a CRM, a newsletter tool), each needs its own correctly configured selector and signing setup; one working doesn't mean they all do.
- Does checking DKIM require access to my mail server?
- Read access or the ability to send a test email through it is usually enough; no changes are made during a check.
- How often should DKIM be checked?
- After any mail server or provider change, or if deliverability drops unexpectedly — DKIM configuration doesn't normally change on its own.