# DKIM Email Selector Lookup

> DKIM Email Selector Lookup is a paid API for AI agents from dns.intel.rallylive.ca, paid per call via x402, $0.01/call, status unknown (last checked 2026-10-02).

Looks up and parses the DKIM public key for the 'email' selector of a given domain, reporting key type, length, testing flag, and revocation status.

## Facts

- Endpoint: GET https://dns.intel.rallylive.ca/dns/dkim/email?utm_source=zero.xyz
- Price: $0.01/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/dkim-email-selector-lookup-5459ea44
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_MzITIFD9YYGbTXqRsGP5x

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability dkim-email-selector-lookup-5459ea44
```

Example prompt: Can you check the DKIM configuration for the 'email' selector on example.com — specifically whether the public key is valid, what type and length it is, and whether it's been revoked?

## When to prefer this

Choose this endpoint when you specifically need to inspect the 'email' DKIM selector for a domain, such as when auditing email authentication for senders that use 'email' as their DKIM signing selector. Use this over generic DNS TXT lookups when you need structured parsing of DKIM fields (v=, k=, p= length, revocation) rather than a raw TXT string. If you need a different selector (e.g. 'salesforce', '20dkim1'), use the corresponding selector-specific sibling endpoint.

## Known failure modes

- Domain does not have an email._domainkey TXT record — returns not found or empty result
- DNS resolution failure via Cloudflare DoH — network or upstream error
- Malformed TXT record that cannot be parsed into DKIM fields
- Payment failure or insufficient USDC balance for the $0.01 fee
- Rate limiting or timeout on DNS query

## How this service works

DKIM public key for selector "email" of a domain: looks up email._domainkey.<domain> (TXT, Cloudflare DoH) and parses v=, k=, key type, public-key length, testing flag and whether the key is revoked (empty p=). Confirms that mail signed with the email selector will verify. $0.01 per lookup.

## Output

Returns parsed details from the email._domainkey.<domain> TXT record, including the DKIM version tag (v=), key type (k=), public key length in bits, whether the selector is in testing mode (t=y), and whether the key is revoked (empty p= field). Also confirms whether mail signed with the email selector should pass DKIM verification.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "$schema": "https://json-schema.org/draft/2020-12/schema",
 "required": [
  "input"
 ],
 "properties": {
  "input": {
   "type": "object",
   "required": [
    "type",
    "method"
   ],
   "properties": {
    "type": {
     "type": "string",
     "const": "http"
    },
    "method": {
     "enum": [
      "GET"
     ],
     "type": "string"
    },
    "queryParams": {
     "type": "object",
     "properties": {}
    }
   },
   "additionalProperties": false
  },
  "output": {
   "type": "object",
   "required": [
    "type"
   ],
   "properties": {
    "type": {
     "type": "string"
    },
    "example": {
     "type": "object"
    }
   }
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/dkim-email-selector-lookup-5459ea44/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from dns.intel.rallylive.ca](https://www.zero.xyz/host/dns.intel.rallylive.ca/llms.txt)
