Inspect

DKIM Inspector: track every DKIM key you publish

Most domains have more DKIM keys published than anyone remembers: one from Google, one from the newsletter tool, one from a vendor that left years ago. DKIM Inspector lists them all and flags the weak ones.

Where to find it
Inspect → DNS Inspector → DKIM Inspector

What you'll see per selector

  • Key strength: 2048-bit is current practice. 1024-bit is flagged as weak; some receivers already treat it as untrustworthy.
  • Where DMARCS learned about it: from a DMARC report, from a DNS scan, or because you added it by hand.
  • Live status: whether the selector still resolves in DNS right now.

Scan DNS

Click Scan DNS to probe a list of common selector names (the ones Google, Microsoft, Mailchimp and others use by default) and discover keys you haven't told DMARCS about.

Read this before scanning. Scan DNS also re-checks every selector you're already tracking, and any that no longer resolve are removed from the list permanently. If you have selectors tracked already, DMARCS asks you to confirm first. If you want a record of a retired selector, note it down before you scan.

What to do about a weak key

Ask the vendor that owns the selector to issue a 2048-bit key, or, if it's a key you control, generate a new one with Smart DKIM under a new selector name, switch your mail server to it, then retire the old one.

Still need a hand?

Email support@dmarcs.com, call +971 4 240 4441, or open a ticket from Support inside the app.

Contact Support