Free tool · keys made in your browser
DKIM record generator
This DKIM generator creates an RSA key pair in your browser and writes the DNS record for it. Publish the public key as a TXT record, install the private key in the software that signs your mail.
Your DKIM record
s202610._domainkey.example.com TXT "v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA…"
The generator needs JavaScript to create a key pair in your browser.
How to use the DKIM generator
- Enter your domain and a selector. The domain is the one in the From address of the mail you sign (or the subdomain you send from). The selector is a name for this key; the generator suggests one based on the current month.
- Keep 2048 bits unless your DNS host can’t store the record (see key sizes below).
- Save the private key. Download it or copy it into the signing software of your mail server or application. PKCS#8 (
BEGIN PRIVATE KEY) is the current standard format; switch to PKCS#1 (BEGIN RSA PRIVATE KEY) if your software asks for it. - Publish the TXT record at your DNS host, with the name and value shown.
- Turn on signing in your mail software with the same selector and domain, then test with the DKIM checker.
The key pair is created by your browser’s Web Crypto API. The private key is never sent to us or anywhere else, and it is gone when you reload the page, so save it before you leave. Treat it like a password: anyone who has it can sign mail as your domain.
Where to publish the DKIM record
DKIM keys live under a fixed subdomain, _domainkey (RFC 6376, section 3.6.2.1). With the selector s202610 and the domain example.com, the record looks like this:
s202610._domainkey.example.com. 3600 IN TXT "v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA…"
| Tag | Meaning |
|---|---|
v=DKIM1 | Version. If present, it must be the first tag. |
k=rsa | Key type. RSA is the default and the type every verifier must support. |
t=y | Optional testing flag: receivers treat signed mail like unsigned mail. |
p= | The public key in base64. An empty p= means the key has been revoked. |
Most DNS hosts want only the part before your domain in the name field:
| DNS host | Name field | Enter | Value field | Note |
|---|---|---|---|---|
| Cloudflare | Name | s202610._domainkey | Content | |
| GoDaddy | Name | s202610._domainkey | Value | Values up to 1,024 characters. |
| Namecheap | Host | s202610._domainkey | Value | Leave out your domain: Namecheap adds it. |
| Amazon Route 53 | Record name | s202610._domainkey | Value | Use the “255-character strings” value from the generator. |
A 2048-bit key makes a record of about 410 characters. A single DNS text string holds at most 255 characters (RFC 1035, section 3.3), so zone files and some DNS hosts need the value as several quoted strings; receivers join them without spaces (RFC 6376, section 3.6.2.2). The generator shows the value both ways and as a zone file line. Each selector may have only one TXT record.
If you publish DKIM for a subdomain such as mail.example.com, the name becomes s202610._domainkey.mail. The DKIM record guide explains the other tags and how receivers check a signature.
Provider-managed DKIM: when not to generate your own key
Most hosted email services create the key pair themselves and keep the private key on their signing servers. With them, a key from this generator is useless: they couldn’t sign with it. Use their records instead:
| Service | What you publish | Who holds the key |
|---|---|---|
| Google Workspace | One TXT record generated in the Admin console; the default selector is google. Choose 2048 bits, or 1024 if your DNS host doesn’t support 2048-bit keys. | |
| Microsoft 365 | Two CNAME records, selector1._domainkey and selector2._domainkey, pointing to values shown in the Defender portal. Microsoft rotates the keys. | Microsoft. A TXT record with your own key “isn’t supported for Microsoft 365”. |
| Twilio SendGrid | With automated security: CNAME records including s1._domainkey and s2._domainkey. | SendGrid, which “manages your DKIM” and rotates between the two selectors. |
| Mailchimp | Two CNAME records shown in your Mailchimp account. | Mailchimp |
| Amazon SES | Easy DKIM: three DNS records. | Amazon |
In Microsoft 365, new DKIM keys default to 1024 bits; Microsoft documents a 2048-bit option through PowerShell (-KeySize 2048), which takes effect at the next key rotation.
When you do need your own key:
- Your own mail server. Postfix, Exim or another MTA with a DKIM signing component reads the private key from a file.
- An application that signs its own mail, for example with a DKIM library.
- Amazon SES with Bring Your Own DKIM (BYODKIM). SES accepts your own RSA key of 1024 to 2048 bits in PKCS#1 or PKCS#8 format. Paste the private key without the
BEGIN/ENDlines and line breaks, and publish the public key as a TXT record atselector._domainkey.example.comwith the valuep=plus the key. - Any other sender whose setup guide asks you to supply a key pair.
Selector names and key rotation
The selector exists so a domain can publish several keys at once (RFC 6376, section 3.1). The RFC advises against reusing a selector for a new key: “A better strategy is to assign new keys to new selectors.” Practical naming rules:
- Use letters, digits and hyphens. Dots are allowed, but each part becomes its own DNS label.
- Encode the date (
s202610) or the sender (crm2026), so you can tell keys apart in DNS and in thes=tag of the signature. - Use a different selector for each service that signs for your domain. Each one holds its own key.
M3AAWG’s DKIM key rotation best practices recommend rotating keys at least every six months. A rotation with this generator:
- Generate a new key pair with a new selector and publish its TXT record.
- Wait until the record resolves (check it with the DKIM checker), then switch your signer to the new private key and selector.
- Keep the old record published for at least seven days (M3AAWG suggests 7 to 30), so mail that was signed before the switch still verifies.
- Revoke the old key by publishing its record with an empty
p=value. M3AAWG recommends this over deleting the record.
DKIM key size: 1024, 2048 or 4096 bits
RFC 8301 sets the rules: signers must use RSA keys of at least 1024 bits and should use at least 2048 bits; verifiers must handle keys from 1024 to 4096 bits and must not accept signatures made with smaller keys. The same RFC requires rsa-sha256 for signing; rsa-sha1 must not be used.
| Key size | TXT value | Strings of 255 characters | Use it when |
|---|---|---|---|
| 1024 bits | 234 characters | 1 | Your DNS host can’t store a longer record. |
| 2048 bits | 410 characters | 2 | Almost always. |
| 4096 bits | 754 characters | 3 | You control the signer and DNS, and every service that needs the key accepts it. Amazon SES BYODKIM, for example, takes at most 2048 bits. |
Character counts are for the record as the generator writes it, without t=y. RFC 6376 already pointed out that large keys “might not fit within a 512-byte DNS UDP response packet” (section 3.3.3). Google Workspace, Microsoft 365 and Amazon SES all offer 2048 bits as their largest size.
The p= value is the public key in SubjectPublicKeyInfo form, which is what openssl rsa -pubout writes and what DKIM records use in practice. RFC 6376 names the bare RSAPublicKey structure, but erratum 3017 (held for the next update of the RFC) notes that the RFC’s own example produces SubjectPublicKeyInfo and that most implementations accept such keys.
Ed25519 keys
RFC 8463 adds a second key type: k=ed25519 with the algorithm ed25519-sha256. Its public keys are much shorter: the p= value is the 32-byte key in base64. The RFC says verifiers must implement it, but RSA remains the type every verifier is required to support (RFC 6376), and RFC 8463 lets signers add a second signature with the new algorithm next to the old one. So if you use Ed25519, sign with an RSA key as well. This generator creates RSA keys only.
Test the DKIM record
DNS changes can take from a few minutes up to the record’s TTL, or the time your DNS provider states, to show up. Then:
- Look up the key with the DKIM checker: enter your domain and selector to confirm the record parses and the key length is right. The link under the generated record fills both in.
- Send a message to a mailbox you control and read the
Authentication-Resultsheader (dkim=passwith your domain) in the email header analyzer.
DKIM is one of three records receivers check. Pair it with an SPF record from the SPF record generator and a DMARC policy from the DMARC generator, so receivers know what to do with mail that fails. The guide to email deliverability shows how the three fit together.
Sources
Checked October 9, 2026: RFC 6376 and its errata; RFC 1035; RFC 8301; RFC 8463; Google Workspace: Set up DKIM; Microsoft: Set up DKIM to sign mail from your Microsoft 365 domain; Twilio SendGrid: DKIM records; Mailchimp: Set up email domain authentication; Amazon SES: Bring your own DKIM; GoDaddy: Add a TXT record; M3AAWG DKIM Key Rotation Best Common Practices (revised March 2019).
Frequently asked questions
How do I create a DKIM record?
What is a DKIM selector?
Should I use a 1024 or 2048 bit DKIM key?
How do I add a DKIM record in Office 365?
How do I add a DKIM record in GoDaddy?
Email validation API
Validate emails in your app
emailvalidation.io checks syntax, MX records and the mailbox over SMTP, flags disposable, role and free addresses and returns a quality score, in one request.
/v1/info Email validation API Read the documentation
100 free validations every month. No credit card required.
GET https://api.emailvalidation.io/v1/info?
{
"email": "support@emailvalidation.io",
"user": "support",
"tag": "",
"domain": "emailvalidation.io",
"format_valid": true,
"mx_found": true,
"smtp_check": true,
"catch_all": null,
"role": true,
"disposable": false,
"free": false,
"score": 0.64,
"state": "deliverable",
"reason": "valid_mailbox",
"did_you_mean": ""
}