Skip to content

What we checkEmailEM-07

DKIM discovery

DKIM signs your mail cryptographically. We look for keys at the selectors common providers use.

Area
Email
Check
EM-07
Included
Free in every scan

What we check

We query a list of well-known DKIM selectors — the names Google, Microsoft, and the major sending platforms publish under.

This is a heuristic and we grade it as information only. A key at a selector we do not know about is invisible to us, and its absence here is not evidence of a problem.

Why it matters

DKIM survives forwarding, which SPF does not: a message forwarded through a mailing list keeps its signature but loses its SPF alignment.

For DMARC to be robust, you want both — either one aligning is enough to pass.

DKIM also travels with the message. A signature added by your mail provider stays valid through a forward, a mailing list, or a shared mailbox — which is why a domain relying on SPF alone sees legitimate mail fail authentication in exactly the cases where a human is least likely to suspect a technical cause.

How to fix it

  1. 1

    Turn on DKIM signing in your mail provider's admin console; they will give you the DNS record to publish.

  2. 2

    Do the same for every service that sends on your behalf.

Common questions

You say DKIM is not discoverable. Is mine broken?
Probably not. There is no way to enumerate DKIM selectors — we can only guess common ones. If your provider's console says signing is on, it is on.
Why is this check informational?
Because a false negative is likely and a low grade for a correctly configured domain would be wrong. It never affects your score.
What key length should I use?
2048-bit. 1024 is still widely deployed and still accepted, but there is no reason to choose it for a new key.

See how your domain does on this check.

All 34 checks, a grade, and the exact fix for anything that isn’t right — in about twenty seconds, no signup.