PostureAudit

DKIM record not found, revoked, or in test mode

If a checker tells you “no DKIM record found”, be careful with that answer. DKIM selectors cannot be discovered from DNS. Any tool reporting absence has guessed at a list of common names and found nothing — which is not the same as proving you have no DKIM.

Why selectors can't be looked up

A DKIM key lives at <selector>._domainkey.yourdomain.com. The selector is an arbitrary string your provider chose. DNS has no way to ask “what names exist under _domainkey?” — you can only ask whether a specific name resolves.

So every DKIM checker works the same way: try a list of selectors that providers commonly use, report what comes back. A domain signing with 2026a._domainkey will look unsigned to all of them.

The reliable way to find your selector: open a message your domain actually sent, view the raw source, and read the DKIM-Signature header. The s= tag is your selector and d= is the signing domain. No guessing required.

What the record means

google._domainkey.example.com.  TXT  "v=DKIM1; k=rsa; p=MIIBIjANBgkq..."
TagMeaning
p=The public key. Empty means the key is revoked.
k=Key type, almost always rsa.
t=yTest mode — receivers are told to ignore failures.

An empty p= is deliberate, not broken

Publishing v=DKIM1; p= revokes that key. It is the correct way to retire a selector. It becomes a problem only when something is still signing with it — then every signature fails, and because the record exists, naive checkers report DKIM as present.

t=y means your DKIM does nothing

Test mode tells receivers to treat failures as passes. It exists for rollout and is routinely left behind afterwards. A domain with t=y has DKIM in appearance only. Remove it once signing is verified.

A wildcard *._domainkey with an empty key

Some domains answer every selector with an empty key — an explicit declaration that they sign nothing. It's deliberate and legitimate for domains that never send mail. It also makes selector-probing tools report a key at every selector they try, which is why a careful checker distinguishes this case instead of reporting dozens of revoked keys.

Key length

1024-bit RSA keys are still common and increasingly discounted. 2048 is the current baseline. Rotating means publishing a new selector, switching signing over to it, and revoking the old one — not editing the existing record, which would break every in-flight message signed with the old key.

DKIM alone doesn't authenticate you

A valid signature proves a message wasn't altered and came from a holder of the key. DMARC is what ties that back to the visible From: address, through alignment: the d= in the signature must match the From domain.

Strict alignment (adkim=s) requires an exact match, so a message signed by mail.example.com fails for a @example.com sender. Relaxed alignment — the default — accepts the subdomain. Worth checking if DKIM passes but DMARC fails anyway.