Back to ConnectedGeek.net

Email Tools

DKIM Checker

Confirm the domain publishes a valid DKIM signing key, and check its strength.

DKIM tags at a glance

TagMeaning
selectorThe label before ._domainkey. Your provider chooses it; it appears as s= in the message header.
v=DKIM1Version tag.
kKey type, normally rsa. Some providers use ed25519.
pThe public key. An empty p= means the key has been revoked.
Key size2048-bit RSA is recommended. 1024-bit still works but is considered weak.

Want the complete picture? The Full Email Check scores SPF, DKIM, DMARC, MTA-STS, TLS reporting, and BIMI together.

Why this matters: what happens without SPF, DKIM, and DMARC

Email was designed without any way to prove who sent a message. SPF, DKIM, and DMARC add that proof. Inbox providers now rely on them to decide whether your mail reaches the inbox, lands in spam, or is refused outright.

RecordWhat it doesWithout it
SPFLists the servers and services allowed to send email as your domain, such as Microsoft 365, Google Workspace, your CRM, and your website.Receivers cannot tell your real mail from a forgery. Mail sent through a service you forgot to list fails the check.
DKIMAdds a digital signature to each message, proving it came from your domain and was not altered on the way.Forwarded mail and mail from marketing platforms often fails authentication, and the message carries no proof of origin.
DMARCTells receivers what to do when a message fails SPF and DKIM, and sends you reports showing who is sending as your domain.Anyone can send email that appears to come from your domain, and you have no visibility of it.

The inbox providers now require them

Google (Gmail) and Yahoo began enforcing sender requirements in 2024, and Microsoft (Outlook.com, Hotmail, and Live) followed in 2025. Every sender needs SPF or DKIM. Businesses that send in volume, including newsletters, invoices, and CRM campaigns, need all three, with DMARC published and the From address aligned with SPF or DKIM. Mail that does not meet these requirements is increasingly sent to spam or rejected, and the rules continue to tighten.

What it costs a business

Mail that never arrivesQuotes, invoices, appointment reminders, and password resets go to spam or bounce. Customers assume you did not respond.
Your domain used for fraudWithout an enforced DMARC policy, criminals can send fake invoices and payment-change requests that appear to come from you, to your own customers and staff.
Damaged sender reputationSpoofed mail and spam complaints lower your domain's reputation, so even your legitimate mail is filtered more aggressively over time.
Wasted marketingCampaigns from your CRM or newsletter platform reach a fraction of your list, and results look worse than they are.

What "done right" looks like

One SPF record listing every service that sends as your domain, within the 10-lookup limit. DKIM signing enabled with a 2048-bit key for each sending service. DMARC published with reports going to a monitored address, then moved from p=none to p=quarantine or p=reject once the reports confirm all legitimate mail passes. Moving too fast blocks your own mail, so the change should be made with the reports in hand.

Not sure your email is set up correctly? We can do it for you.

Our technicians correct DNS and email authentication records every day. Tell us about your domain and we will make the changes, confirm they work, and explain what we did.

Fix this for me →

Stay Connected!

DNS changes, email problems, or a domain migration giving you trouble? Our technicians can sort it out and keep your business online.

→ Contact Us Today!