Every selector, found and graded

Your provider issues the keypair and signs your mail, exactly as it does now. We find every selector signing as your domain, grade the key strength, and flag the faults that make a signature decorative.

The scan needs no account. Plans start at 12 €/mo with a 14-day trial.

DKIM selectors0 found
  • selector1Microsoft 3652048-bit
  • googleGoogle Workspace2048-bit
  • mandrillMailchimp1024-bit
  • zohoZoho Mailt=y
Verdict

2 of 4 selectors sign without protecting anything: one key too short to mean much, one publishing t=y, which tells receivers to ignore its failures.

A signature that verifies nothing still looks like a signature

DKIM fails quietly in two ways that no inbox will ever show you, and both are common enough that most domains have one.

Selectors you forgot about

Third-party services sign with their own selectors. We find each one, including the ones nobody remembers adding, and name the service behind it.

Keys too short to matter

1024-bit RSA is still widespread and no longer meaningful protection. Every key is graded against the 2048-bit minimum.

Testing mode, left on

A record publishing t=y tells receivers to ignore signature failures. The signature is present, the protection is not, and nothing anywhere says so.