DMARC Checker
Inspect DMARC policy, reporting configuration and enforcement posture.
Look up a DKIM public key by domain and selector and inspect key type, public-key presence and flags.
Your input is processed only as required by this tool.
DKIM signs email with a private key while receivers fetch the corresponding public key from DNS. Because DKIM records live under a selector-specific _domainkey name, this checker asks for both the domain and selector, then inspects the published TXT record and key tags.
A record with a public key means DNS exposes material that receivers can use for DKIM verification. The result does not prove that a particular message was signed correctly; message verification requires the actual headers and signature.
Selectors are chosen by the sending provider and cannot be reliably guessed for every domain. You must provide the selector used by the sender, such as google, selector1 or a provider-specific value.
It is the label that identifies a particular DKIM key under selector._domainkey.example.com.
Not reliably. DNS does not provide a standard directory of all DKIM selectors, so the sender or provider normally supplies it.