DKIM record not found, revoked, or in test mode
If a checker tells you “no DKIM record found”, be careful with that answer. DKIM selectors cannot be discovered from DNS. Any tool reporting absence has guessed at a list of common names and found nothing — which is not the same as proving you have no DKIM.
Why selectors can't be looked up
A DKIM key lives at <selector>._domainkey.yourdomain.com.
The selector is an arbitrary string your provider chose. DNS has no way to ask
“what names exist under _domainkey?” — you can only ask whether a
specific name resolves.
So every DKIM checker works the same way: try a list of selectors that
providers commonly use, report what comes back. A domain signing with
2026a._domainkey will look unsigned to all of them.
DKIM-Signature header. The s= tag is your selector
and d= is the signing domain. No guessing required.
What the record means
google._domainkey.example.com. TXT "v=DKIM1; k=rsa; p=MIIBIjANBgkq..."
| Tag | Meaning |
|---|---|
p= | The public key. Empty means the key is revoked. |
k= | Key type, almost always rsa. |
t=y | Test mode — receivers are told to ignore failures. |
An empty p= is deliberate, not broken
Publishing v=DKIM1; p= revokes that key. It is the correct way
to retire a selector. It becomes a problem only when something is still signing
with it — then every signature fails, and because the record exists, naive
checkers report DKIM as present.
t=y means your DKIM does nothing
Test mode tells receivers to treat failures as passes. It exists for rollout
and is routinely left behind afterwards. A domain with t=y has
DKIM in appearance only. Remove it once signing is verified.
A wildcard *._domainkey with an empty key
Some domains answer every selector with an empty key — an explicit declaration that they sign nothing. It's deliberate and legitimate for domains that never send mail. It also makes selector-probing tools report a key at every selector they try, which is why a careful checker distinguishes this case instead of reporting dozens of revoked keys.
Key length
1024-bit RSA keys are still common and increasingly discounted. 2048 is the current baseline. Rotating means publishing a new selector, switching signing over to it, and revoking the old one — not editing the existing record, which would break every in-flight message signed with the old key.
DKIM alone doesn't authenticate you
A valid signature proves a message wasn't altered and came from a holder of
the key. DMARC is what ties that back to the visible From:
address, through alignment: the d= in the signature must match the
From domain.
Strict alignment (adkim=s) requires an exact match, so a
message signed by mail.example.com fails for a
@example.com sender. Relaxed alignment — the default — accepts the
subdomain. Worth checking if DKIM passes but DMARC fails anyway.