If your email is failing DKIM checks, it usually means one of several things is wrong. Here is how to diagnose and fix it.
The free InboxProof DKIM checker verifies your DKIM record, checks the key strength, and tells you exactly what to fix. No signup.
Run the free checkWhen a receiving server says your email "failed DKIM," it means one of these:
Run this command to check your DKIM record:
dig +short TXT google._domainkey.yourdomain.com
Replace google with your actual DKIM selector. If the command returns nothing, your DKIM record is missing.
Make sure the DKIM selector in your DNS matches the one your email provider uses. For example, if you use Google Workspace, the selector is usually google. If you use Microsoft 365, it is usually selector1 or selector2.
If they do not match, DKIM will fail.
Modern DKIM keys should be at least 1024 bits. If your key is 512 bits, many receiving servers will reject it.
Run the free InboxProof DKIM checker to verify your key strength.
For DKIM to pass, the domain in your DKIM signature must align with the domain in your "From" header. If they do not match, DKIM will fail.
For example, if your "From" domain is yourdomain.com, your DKIM signature must also be for yourdomain.com (or a subdomain of it).
After making the changes, run the free InboxProof DKIM checker to confirm your DKIM record is configured correctly. The checker verifies:
Run the free DKIM checker and see if your DKIM record is configured correctly.
Run the free checkWant this checked automatically every day? Inboxproof Pro monitors your domain around the clock and alerts you the moment a record breaks or an IP gets listed. See pricing →
Related: SPF vs DKIM vs DMARC · SPF record not working? · How to set up a DMARC record · Gmail SMTP error 550-5.7.26