Enter a domain above. dkim.fyi looks at its MX, SPF and DMARC records to decide which of about two hundred known selectors to try first, then checks them all.
A miss is inconclusive
DKIM selectors are not enumerable through ordinary DNS. A miss against this list does not prove DKIM is absent.
The authoritative selector is the s= value in a DKIM-Signature header paired with its d= signing domain.
More limitations Some providers generate random, tenant-specific, account-ID, timestamp, or administrator-defined selectors that cannot be represented by a finite wordlist. Several selectors are historical or observed probe candidates rather than current contractual defaults. Use status, confidence, selector_mode, notes, and source_urls. Check for _domainkey wildcards before treating probe hits as real selectors. Resolve both TXT and CNAME chains and detect revoked keys with an empty p= value. A provider-operated-domain selector is not necessarily published on customer domains; consult customer_domain_applicability.