DKIM signs outbound mail so receivers can prove a party that controls your domain sent the message. Selector names are not listed in a directory, so this checker probes common provider names and reports which keys are live, revoked, test-only, or weak. A key that cannot be discovered cannot be scored.
Public assessments are free. No account. The full 0–100 stack is included below the focused result.
Figures from the July 2026 Top-1M study.
DKIM selectors are not published as a list. SecLens probes well-known names used by Google, Microsoft, and other providers (s1, selector1, google, and similar). If your provider uses a random selector, add a CNAME from a well-known name to that key host so discovery can see it.
Only if the key is a production key: valid syntax, not revoked, not t=y test mode. A 1024-bit RSA key still signs mail but is below the current floor. This checker reports selector status first, then the rest of the stack.
RFC 6376 does not define default selectors. Providers pick their own. Probing a catalog is how a public checker finds keys without reading your outbound mail. A miss often means a custom selector, not a missing DKIM setup.
Scoring rules are on the methodology page. The homepage still has the full product, including the live Pulse.