# DKIM Selector k1 Lookup

> DKIM Selector k1 Lookup is a paid API for AI agents from dns.intel.rallylive.ca, paid per call via x402, $0.01/call, status unknown (last checked 2026-10-02).

Looks up and parses the DKIM public key for the 'k1' selector of a given domain via Cloudflare DoH, returning key type, length, testing flag, and revocation status.

## Facts

- Endpoint: GET https://dns.intel.rallylive.ca/dns/dkim/k1?utm_source=zero.xyz
- Price: $0.01/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/dkim-selector-k1-lookup-95e4915f
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_kaiZwDs6z7RRsqQYIJNH3

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability dkim-selector-k1-lookup-95e4915f
```

Example prompt: Can you check the DKIM k1 selector for example.com and tell me if the key is valid, what type it is, how long the key is, and whether it's been revoked?

## When to prefer this

Use this endpoint when you specifically need to inspect the DKIM 'k1' selector for a domain — checking key validity, type, strength, and revocation status. Prefer this over generic DNS TXT lookups when you want structured, parsed DKIM fields rather than raw TXT data. Ideal for email deliverability audits, domain security checks, and debugging DKIM signing failures for the k1 selector specifically.

## Known failure modes

- Domain does not exist or has no DNS — returns empty or NXDOMAIN result
- No k1._domainkey record found — key absent or selector not published
- Revoked key (empty p=) — lookup succeeds but key is invalid
- Malformed TXT record — parsing may fail or return partial data
- Cloudflare DoH timeout — transient DNS resolution failure
- Invalid domain input — may return error or empty response

## How this service works

DKIM public key for selector "k1" of a domain: looks up k1._domainkey.<domain> (TXT, Cloudflare DoH) and parses v=, k=, key type, public-key length, testing flag and whether the key is revoked (empty p=). Confirms that mail signed with the k1 selector will verify. $0.01 per lookup.

## Output

Returns parsed DKIM TXT record data for the k1._domainkey.<domain> record, including: v= tag (DKIM version), k= tag (key type, e.g. rsa), the public key itself, key length in bits, whether the testing flag (t=y) is set, and whether the key is revoked (empty p= field). Indicates whether mail signed with the k1 selector should verify successfully.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "$schema": "https://json-schema.org/draft/2020-12/schema",
 "required": [
  "input"
 ],
 "properties": {
  "input": {
   "type": "object",
   "required": [
    "type",
    "method"
   ],
   "properties": {
    "type": {
     "type": "string",
     "const": "http"
    },
    "method": {
     "enum": [
      "GET"
     ],
     "type": "string"
    },
    "queryParams": {
     "type": "object",
     "properties": {}
    }
   },
   "additionalProperties": false
  },
  "output": {
   "type": "object",
   "required": [
    "type"
   ],
   "properties": {
    "type": {
     "type": "string"
    },
    "example": {
     "type": "object"
    }
   }
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/dkim-selector-k1-lookup-95e4915f/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from dns.intel.rallylive.ca](https://www.zero.xyz/host/dns.intel.rallylive.ca/llms.txt)
