DKIM Validator API

GET

Catch weak signing keys and broken DKIM setups on any domain.

DKIM Validator checks the DomainKeys Identified Mail (DKIM) DNS records for a domain to verify that they are present and correctly formatted.

Try it — live request, no key required

Request
GETapi.apiverve.com/v1/dkimvalidator?domain=github.com
Query parameters
Verification
Format

No key required to try it. Get a key to use it in your app.

Example
{
  "status": "ok",
  "error": null,
  "data": {
    "selector": "s1",
    "host": "github.com",
    "dkim_host": "s1._domainkey.github.com",
    "cname_target": null,
    "has_dkim_record": true,
    "dkim_record": "k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyn3fMCVpb7ryIRKOGXhXVGYmsWUitNlSckqGHOwNFZgFadplOrD+Qzf1XQkP7MH/VB/97DsAAJGtEXW1Uq71Hjnfr/DuBN/YfjF/gU70qEFb7q1sdIiNtjFL2TkOpoW+X/bhhPNheW/fYwyFb6ZHFM6LTgXyuimWRHTOUP3VjZzhNVda79nt+2WZYbS4l8HdMgWpTNHjpVw5PtXESA9KBg/evSRk5fIaXIX5eRXW3baoV9yVzD8O29/IL/DiSk+yNvaO0EHL5c4yGuZJhGzvpiznb2IDVdemJK4Dqzdy5FTN/SGYZhAEr7MguG3Z314hMS2scgMsOMgB64uj/6+6UwIDAQAB",
    "dkim_records_count": 1,
    "key_type": "rsa",
    "issues_found": [
      {
        "code": "V_TAG_NOT_FOUND",
        "type": "warning",
        "message": "The v tag is missing"
      },
      {
        "code": "STRICT_MODE",
        "type": "info",
        "message": "Strict flag set (t=s): the i= identity domain must exactly match d= (no subdomains)"
      }
    ],
    "valid": true,
    "key_bits": 2048,
    "is_test_mode": false,
    "risk_score": 0,
    "risk_level": "low"
  }
}

About the DKIM Validator API

This tool inspects the DKIM record by performing DNS lookups for common selectors. It validates the syntax, surfaces the public-key length in bits, flags testing mode, and derives a composite email-signing posture score so you can tell at a glance whether a domain's DKIM key actually protects its mail.

What people use it for

Email Service Onboarding
When a new customer connects a sending domain, verify their public key length and check whether testing mode is active before sending campaigns.
Mail Security Auditing
To prevent spoofing across corporate domains, security analysts inspect DNS selectors to confirm valid DKIM records and flag keys shorter than 2048 bits.
Sender Deliverability Diagnostics
Deliverability consultants check whether outbound domains publish valid DKIM public keys or point to unresolved CNAME targets when diagnosing inbox placement drops.
Tenant Domain Verification
Flag missing or misconfigured DKIM records during custom domain setup so software platforms can alert workspace admins before outgoing notifications fail authentication.

Ways to call it

One endpoint, many ways in — REST with JSON, XML, YAML and CSV, plus GraphQL and an MCP interface for AI agents.

JSON
Default REST response
XML
Markup format
YAML
Human-readable
CSV
Tabular export
Beta
GraphQL
Query language
New
MCP
For AI agents

How it compares

Side by side with the tools people weigh DKIM Validator against — what each one is better at, in plain terms.

Other ways to use DKIM Validator

Same data, same APIVerve account, same credit balance — one key works on all of them.

Questions.

Common questions about the DKIM Validator API.

Read the docs →
How many domain checks does the Free plan cover?
The Free plan includes 200 monthly credits, which covers 20 DKIM checks at 10 credits each. Paid plans like Starter provide 200,000 credits each month, covering up to 20,000 checks at roughly $0.0015 per call or $1.50 per 1,000 calls. Unused credits do not roll over, and requests return HTTP 429 when limits are reached.
Do I get the DKIM risk score and detected issues on the Free plan?
No, the risk score, risk level, and detailed issues list are premium fields reserved for paid plans. Free requests return core validation data like record existence, key length in bits, test mode status, and validity. Subscribing to Starter or higher unlocks the composite risk score and issue breakdowns.
What happens if I do not know the DKIM selector for a domain?
You can leave the selector parameter empty. When omitted, DKIM Validator queries a list of common selectors to check for existing records. If the domain uses a custom or provider-specific selector, pass it in the selector parameter to validate that specific DNS record.
How fresh is the DKIM verification data?
All verification data is resolved in real time. Each request performs live DNS lookups against the specified domain and selector, giving you the active DNS record, key length, and configuration flags without cached or outdated data.
What does the API return if a domain has no DKIM record?
If no record is published for the queried domain and selector, the response sets has_dkim_record to false, valid to false, and key_bits to 0. The request returns successfully without breaking your integration, letting your application handle missing records gracefully.
Can I use DKIM validation results inside my own commercial deliverability tool?
Yes, you can build DKIM checks directly into your commercial monitoring platform, onboarding flow, or security audit tool with any paid plan. Commercial use is prohibited on the Free plan, and you may not resell or redistribute the raw API output as a standalone data service.

Ready to build with DKIM Validator? Start with 200 free credits — one key unlocks all 300+ APIs.

Explore the catalog

300+ APIs on the same key and the same response shape.

Browse all APIs