# DKIM Default Selector Public Key Lookup

> DKIM Default Selector Public Key Lookup is a paid API for AI agents from dns.intel.rallylive.ca, paid per call via x402, $0.01/call, status unknown (last checked 2026-10-02).

Looks up and parses the DKIM public key for the 'default' selector of a given domain via Cloudflare DoH, returning key type, length, testing status, and revocation state.

## Facts

- Endpoint: GET https://dns.intel.rallylive.ca/dns/dkim/default?utm_source=zero.xyz
- Price: $0.01/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/dkim-default-selector-public-key-lookup-612e12a8
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_vzw-HpXhP8qttZPDpcIFj

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability dkim-default-selector-public-key-lookup-612e12a8
```

Example prompt: Can you check the DKIM default selector for example.com — I want to know if the key is valid, what type and length it is, and whether it's been revoked or is just in testing mode?

## When to prefer this

Use this endpoint when you specifically need to inspect the 'default' DKIM selector for a domain, including key metadata like type, length, testing status, and revocation. Prefer this over generic DNS TXT lookups when you need structured DKIM field parsing rather than raw TXT data. Choose sibling selector-specific endpoints (k1, shopify2, etc.) when targeting other named selectors.

## Known failure modes

- Domain has no default._domainkey TXT record — returns not found or empty result
- Key is revoked (p= is empty) — returned as a parsed flag rather than an error
- DNS lookup failure via Cloudflare DoH — network or upstream error
- Malformed TXT record that cannot be parsed into DKIM fields
- Domain does not exist or is invalid — DNS NXDOMAIN response

## How this service works

DKIM public key for selector "default" of a domain: looks up default._domainkey.<domain> (TXT, Cloudflare DoH) and parses v=, k=, key type, public-key length, testing flag and whether the key is revoked (empty p=). Confirms that mail signed with the default selector will verify. $0.01 per lookup.

## Output

Returns parsed details from the default._domainkey.<domain> TXT record including the DKIM version tag (v=), key type (k=), public key material, key length in bits, whether the domain is in testing mode, and whether the key has been revoked (empty p= field). Confirms whether mail signed with this selector can be verified.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "$schema": "https://json-schema.org/draft/2020-12/schema",
 "required": [
  "input"
 ],
 "properties": {
  "input": {
   "type": "object",
   "required": [
    "type",
    "method"
   ],
   "properties": {
    "type": {
     "type": "string",
     "const": "http"
    },
    "method": {
     "enum": [
      "GET"
     ],
     "type": "string"
    },
    "queryParams": {
     "type": "object",
     "properties": {}
    }
   },
   "additionalProperties": false
  },
  "output": {
   "type": "object",
   "required": [
    "type"
   ],
   "properties": {
    "type": {
     "type": "string"
    },
    "example": {
     "type": "object"
    }
   }
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/dkim-default-selector-public-key-lookup-612e12a8/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from dns.intel.rallylive.ca](https://www.zero.xyz/host/dns.intel.rallylive.ca/llms.txt)
