Your provider issues the keypair and signs your mail, exactly as it does now. We find every selector signing as your domain, grade the key strength, and flag the faults that make a signature decorative.
The scan needs no account. Plans start at 12 €/mo with a 14-day trial.
2 of 4 selectors sign without protecting anything: one key too short to mean much, one publishing t=y, which tells receivers to ignore its failures.
DKIM fails quietly in two ways that no inbox will ever show you, and both are common enough that most domains have one.
Third-party services sign with their own selectors. We find each one, including the ones nobody remembers adding, and name the service behind it.
1024-bit RSA is still widespread and no longer meaningful protection. Every key is graded against the 2048-bit minimum.
A record publishing t=y tells receivers to ignore signature failures. The signature is present, the protection is not, and nothing anywhere says so.