Send an email, see how it was signed

Some systems sign with selectors nobody could guess: random strings generated per account or per key rotation. The surest way to find them is a message the system really sent. Get a throwaway address, send any email to it, and dkim.fyi shows every DKIM signature on it as a receiver sees it: selector and signing domain, the key published for them, and whether the header signature verifies.

01Get an address

A fresh, random address on dkim.fyi. It accepts mail for 24 hours and is forgotten when you delete it.

02Send any email to it

Send it from the system you want to check: your mail client, your application’s SMTP path, a marketing or support platform. The subject and body do not matter and are never read. Nothing is sent back.

03Results appear here

Each message shows up here within a few seconds of arriving, with every signature on it.

What we keep

  • Read: the header block of each message, and nothing after it. Reading stops at the blank line that ends the headers, so the body and any attachments are never read.
  • Kept for 24 hours, or until you press Delete now: the analysis shown on this page. For each message: when it arrived, the From domain (not the address), each signature’s d=, s=, algorithm and canonicalisation, the key check, whether the header signature verified, and the receiving server’s pass/fail results. For the address: a one-way hash of it, when it was created and how many messages arrived. Expired addresses and their results are deleted within the hour.
  • Never read or kept: the body, the subject, any email address (sender, recipient or From), the Message-ID, the Received chain, the sender’s IP address, raw header values and the signature values themselves.
  • In this tab only: the address, so a reload keeps your results. It is held in session storage, never put in the URL, and forgotten when you close the tab or press Delete now.
  • A private catalog: each signing domain and selector pair that arrives, with what was learned about its key and when it was first and last seen, so dkim.fyi can recognise selectors nobody could guess. It is not linked to your address or this session, and it is not published.
  • Nothing is sent back: no reply, and nothing is forwarded.

If your domain publishes a DMARC p=reject policy and the message is unsigned or misaligned, it never arrives, which is itself the diagnosis.