DKIM Record Generator - Create DKIM Keys and the DNS TXT Record
DKIM Record Generator
Signing keys and the DNS record that publishes them
Ready to Publish
Host name, TXT value and a zone-file line, with long keys split into 255-character strings.
Keys Made Locally
The private key is generated in your browser for you to install on your mail server.
Completes Your Setup
Pair it with the SPF and DMARC generators, then test with the email deliverability checker.
Private
Everything runs in your browser; nothing you paste is uploaded.
How DKIM Works
DKIM (DomainKeys Identified Mail) lets your mail server sign outgoing messages with a private key. Receivers look up the matching public key in DNS at selector._domainkey.yourdomain and check the signature, proving the message really came from your domain and was not altered. The selector is a label of your choice, which lets you run several keys and rotate them.
Use 2048-bit RSA: 1024-bit keys are considered weak, and Ed25519 is not yet verified by every receiver, so publish it only alongside an RSA key. Most DNS control panels accept the long value directly and split it themselves; BIND-style zone files need the quoted pieces shown above. Hosted email services such as Google Workspace and Microsoft 365 generate their own DKIM keys, so use their admin console instead.
Key Takeaways
- 2048-bit RSA: The safe default for DKIM today.
- Never publish the private key: Only the p= public key goes into DNS.
- Rotate with selectors: Publish a new selector, switch signing, then retire the old one.