DKIM Record Generator - Create DKIM Keys and the DNS TXT Record

AdSense Placeholder
Slot: header_tool

DKIM Record Generator

Signing keys and the DNS record that publishes them

DNS host / name

AdSense Placeholder
Slot: tool_mid_article

Ready to Publish

Host name, TXT value and a zone-file line, with long keys split into 255-character strings.

Keys Made Locally

The private key is generated in your browser for you to install on your mail server.

Completes Your Setup

Pair it with the SPF and DMARC generators, then test with the email deliverability checker.

Private

Everything runs in your browser; nothing you paste is uploaded.

How DKIM Works

DKIM (DomainKeys Identified Mail) lets your mail server sign outgoing messages with a private key. Receivers look up the matching public key in DNS at selector._domainkey.yourdomain and check the signature, proving the message really came from your domain and was not altered. The selector is a label of your choice, which lets you run several keys and rotate them.

Use 2048-bit RSA: 1024-bit keys are considered weak, and Ed25519 is not yet verified by every receiver, so publish it only alongside an RSA key. Most DNS control panels accept the long value directly and split it themselves; BIND-style zone files need the quoted pieces shown above. Hosted email services such as Google Workspace and Microsoft 365 generate their own DKIM keys, so use their admin console instead.

Key Takeaways

  • 2048-bit RSA: The safe default for DKIM today.
  • Never publish the private key: Only the p= public key goes into DNS.
  • Rotate with selectors: Publish a new selector, switch signing, then retire the old one.
AdSense Placeholder
Slot: footer_leaderboard