DKIM Selector Report 2026: 1,247 Domains Analyzed
Published September 2026 · By The InboxGreen Team · Methodology
We checked for DKIM records across the same 1,247 domains used in our SPF Mistakes and DMARC Enforcement reports. 22.6% of domains had no DKIM record found on any common selector. Of those that did have DKIM, 11.8% were still using RSA-1024 keys — a key length that NIST deprecated in 2015 and that Gmail and Yahoo now treat as a red flag.
Key Findings
22.6%
of domains had no DKIM record found on any common selector
11.8%
of domains with DKIM were still using RSA-1024 keys, deprecated since 2015
18.9%
of domains with DKIM present still had DMARC failing due to alignment mismatch
62.4%
of domains with DKIM used RSA-2048, the current recommended minimum
DKIM Presence Across All 1,247 Domains
DKIM records live at selector._domainkey.yourdomain.com. To check them, you need to know which selector your email provider uses. InboxGreen checks a list of the most common selectors (see methodology). A domain showing as "not found" means no DKIM record appeared on any selector in that list — it is possible a non-standard selector exists, but that would itself be a configuration problem worth fixing.
The 22.6% figure is notably higher than the 14% we found in the June industry benchmark, which scanned 186 well-known company domains. The gap is expected: established SaaS companies and ESPs treat DKIM setup as standard practice. User-submitted domains skew toward smaller businesses and developers who are still working through their email authentication setup.
Finding 1: RSA-1024 Still In Use (11.8% of DKIM-enabled domains)
Of the 965 domains where DKIM was found, 114 (11.8%) were using RSA-1024 keys. RSA-1024 has been considered cryptographically weak since at least 2010. NIST formally deprecated it in 2015. Google began issuing warnings about 1024-bit DKIM keys in Gmail postmaster guidance in 2023, and Yahoo's 2024 bulk sender requirements explicitly recommend RSA-2048 or higher.
A 1024-bit key can still be verified and will still pass DKIM in most cases today, but the direction from major inbox providers is clear: 1024-bit keys are being phased out. Domains running on 1024-bit keys should rotate to 2048-bit as part of any DNS maintenance window.
DKIM key length across 965 domains with DKIM present
Bar width scaled to 62.4% maximum. "Undetermined" means the key was present but too long or formatted in a way that prevented automatic length extraction from the DNS lookup.
How to check your key length
Run a DKIM lookup for your domain using the DKIM Checker. The raw record contains p= followed by the Base64-encoded public key. A 1024-bit key encodes to roughly 216 Base64 characters. A 2048-bit key encodes to roughly 392 characters. If your key looks short (under 250 Base64 characters), you are likely on 1024-bit.
To rotate: generate a new keypair in your email provider's admin panel (Google Workspace, Microsoft 365, Brevo, etc.), publish the new public key in DNS, verify it, then delete the old selector record.
Finding 2: Which Selectors Are Most Common
The selector name reveals which email provider or configuration a domain is using. The breakdown below shows what InboxGreen found most often across the 965 domains where DKIM was present.
Google Workspace is the most common sending platform among domains in this dataset, accounting for nearly a third of all DKIM-enabled domains. The google selector has been Google Workspace's default for several years; domains on newer Google Workspace configurations sometimes also use google2.
The 24% "other" category includes ESP-specific selectors like SendGrid's s1 and s2 (distinct from Fastmail's s1), Mailgun's randomized selectors, Amazon SES's amazonses prefix, and entirely custom selector names that organizations use when managing their own DKIM keys.
Finding 3: No DKIM Correlates Strongly with Weak DMARC
Among the 282 domains with no DKIM found, 71% also had DMARC at p=none or no DMARC record at all. This pattern appeared in the DMARC report too, in reverse: domains with weak DMARC tended to have weak SPF. All three authentication layers tend to move together — domains that have addressed one have usually addressed the others.
DMARC status among 282 domains with no DKIM found
This matters because DMARC enforcement depends on at least one of SPF or DKIM being aligned. A domain with p=reject but no DKIM is relying entirely on SPF alignment for DMARC to pass. SPF alignment breaks on forwarded email (which is extremely common) because forwarding changes the sending IP without changing the From header. Without DKIM as a backup, forwarded emails from your domain fail DMARC — and with p=reject, they get blocked.
Finding 4: DKIM-to-DMARC Alignment Gap (18.9% of DKIM-enabled domains)
Having DKIM published does not guarantee DMARC passes. DMARC requires alignment: the d= domain in the DKIM-Signature header must match (or be a subdomain of) the From header domain. When an ESP sends mail using their own DKIM keys signed to their own domain, DKIM passes for the ESP's domain but fails alignment with your From address.
Of the 182 domains with alignment mismatches, the most common cause was third-party senders (ESPs, transactional email services) that sign with their own domain rather than the customer's domain. The fix is to configure the sending service to sign with your domain's DKIM key — most major providers support this under "custom DKIM" or "domain authentication" settings. See the DMARC alignment failure fix guide.
DKIM Health Summary
| Status | Domains | % of total | Key action |
|---|---|---|---|
| DKIM present, RSA-2048+, aligned | 783 | 62.8% | No action needed |
| DKIM present, RSA-1024 (weak key) | 114 | 9.1% | Rotate to RSA-2048 |
| DKIM present, alignment failing | 182 | 14.6% | Configure custom DKIM in ESP |
| No DKIM found | 282 | 22.6% | Enable DKIM in email provider |
| Note: the "DKIM present, RSA-1024" group overlaps with the alignment calculation. Total exceeds 100% in some groupings because individual domains can have multiple issues simultaneously. | |||
Check and Fix Your DKIM
Look up your DKIM record by domain and selector. Shows the raw key and whether it is present at the expected host.
Step-by-step guide for enabling DKIM in Google Workspace, Microsoft 365, and major ESPs.
DKIM passes but DMARC still fails — why this happens and how to configure your ESP to sign with your domain.
Check SPF, DKIM, and DMARC alignment together for any domain. Free, no login required.
Cite this report
InboxGreen Team. DKIM Selector Report 2026: 1,247 Domains Analyzed. InboxGreen.email, September 2026. Available at: https://inboxgreen.email/research/dkim-selector-report-2026
Same dataset as the SPF Mistakes Report and DMARC Enforcement Report 2026. 1,247 unique domains. Selectors checked May 1 to July 10, 2026.
Check your DKIM record now
Free lookup by domain and selector. No login required.
Methodology
Dataset: The same 1,247 unique domains from the SPF Mistakes Report 2026 and DMARC Enforcement Report 2026. Domains were submitted to InboxGreen for checking between May 1 and July 10, 2026. Only unique apex domains; subdomains and duplicate submissions excluded.
DKIM lookup method: InboxGreen queries TXT records at selector._domainkey.domain.com using PHP's dns_get_record() against public DNS resolvers. A domain is counted as "DKIM found" if at least one selector in the checked list returns a valid v=DKIM1 TXT record.
Selectors checked: google, google2, selector1, selector2, s1, s2, fm1, fm2, fm3, k1, k2, k3, default, dkim, mail, email, mta, smtp, amazonses, mg, mailgun, sendgrid, sg, brevo, mxe, zoho, fastmail, yandex, protonmail, pm, mandrill, sparkpost, mailjet.
Key length detection: The p= value in the DKIM record is the Base64-encoded public key. Key length is estimated from the Base64 string length: under 260 characters indicates RSA-1024; 360-420 characters indicates RSA-2048; above 700 indicates RSA-4096. Ed25519 keys are identified by the k=ed25519 tag. "Undetermined" means the key was present but formatted across multiple TXT chunks or otherwise could not be auto-classified.
Alignment check: DKIM alignment is assessed by comparing the d= domain in the DKIM-Signature header (where available from the InboxGreen check result) against the apex domain from the From address. Relaxed alignment (subdomain match) is accepted.
Limitations: This analysis can only check selectors in the known list. Custom or rotating selectors not on this list will cause a domain to appear as "DKIM not found" even if a valid record exists. Key length estimation from Base64 length is approximate. Alignment data is available only for domains where a full email was tested, not for DNS-only lookups.