Free tool · keys made in your browser

DKIM record generator

This DKIM generator creates an RSA key pair in your browser and writes the DNS record for it. Publish the public key as a TXT record, install the private key in the software that signs your mail.

The domain in the From address of the mail you sign, or the subdomain you send from.

A name for this key. A new key gets a new selector, so a date such as s202610 works well.

Key size

Recommended. RFC 8301 asks signers to use at least 2048 bits.

The keys are created by your browser's Web Crypto API. The private key never leaves this page: nothing you enter or generate is sent to us.

Your DKIM record

s202610._domainkey.example.com  TXT  "v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA…"

The generator needs JavaScript to create a key pair in your browser.

How to use the DKIM generator

  1. Enter your domain and a selector. The domain is the one in the From address of the mail you sign (or the subdomain you send from). The selector is a name for this key; the generator suggests one based on the current month.
  2. Keep 2048 bits unless your DNS host can’t store the record (see key sizes below).
  3. Save the private key. Download it or copy it into the signing software of your mail server or application. PKCS#8 (BEGIN PRIVATE KEY) is the current standard format; switch to PKCS#1 (BEGIN RSA PRIVATE KEY) if your software asks for it.
  4. Publish the TXT record at your DNS host, with the name and value shown.
  5. Turn on signing in your mail software with the same selector and domain, then test with the DKIM checker.

The key pair is created by your browser’s Web Crypto API. The private key is never sent to us or anywhere else, and it is gone when you reload the page, so save it before you leave. Treat it like a password: anyone who has it can sign mail as your domain.

Where to publish the DKIM record

DKIM keys live under a fixed subdomain, _domainkey (RFC 6376, section 3.6.2.1). With the selector s202610 and the domain example.com, the record looks like this:

s202610._domainkey.example.com.  3600  IN  TXT  "v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA…"
TagMeaning
v=DKIM1Version. If present, it must be the first tag.
k=rsaKey type. RSA is the default and the type every verifier must support.
t=yOptional testing flag: receivers treat signed mail like unsigned mail.
p=The public key in base64. An empty p= means the key has been revoked.

Most DNS hosts want only the part before your domain in the name field:

DNS hostName fieldEnterValue fieldNote
CloudflareNames202610._domainkeyContent
GoDaddyNames202610._domainkeyValueValues up to 1,024 characters.
NamecheapHosts202610._domainkeyValueLeave out your domain: Namecheap adds it.
Amazon Route 53Record names202610._domainkeyValueUse the “255-character strings” value from the generator.

A 2048-bit key makes a record of about 410 characters. A single DNS text string holds at most 255 characters (RFC 1035, section 3.3), so zone files and some DNS hosts need the value as several quoted strings; receivers join them without spaces (RFC 6376, section 3.6.2.2). The generator shows the value both ways and as a zone file line. Each selector may have only one TXT record.

If you publish DKIM for a subdomain such as mail.example.com, the name becomes s202610._domainkey.mail. The DKIM record guide explains the other tags and how receivers check a signature.

Provider-managed DKIM: when not to generate your own key

Most hosted email services create the key pair themselves and keep the private key on their signing servers. With them, a key from this generator is useless: they couldn’t sign with it. Use their records instead:

ServiceWhat you publishWho holds the key
Google WorkspaceOne TXT record generated in the Admin console; the default selector is google. Choose 2048 bits, or 1024 if your DNS host doesn’t support 2048-bit keys.Google
Microsoft 365Two CNAME records, selector1._domainkey and selector2._domainkey, pointing to values shown in the Defender portal. Microsoft rotates the keys.Microsoft. A TXT record with your own key “isn’t supported for Microsoft 365”.
Twilio SendGridWith automated security: CNAME records including s1._domainkey and s2._domainkey.SendGrid, which “manages your DKIM” and rotates between the two selectors.
MailchimpTwo CNAME records shown in your Mailchimp account.Mailchimp
Amazon SESEasy DKIM: three DNS records.Amazon

In Microsoft 365, new DKIM keys default to 1024 bits; Microsoft documents a 2048-bit option through PowerShell (-KeySize 2048), which takes effect at the next key rotation.

When you do need your own key:

  • Your own mail server. Postfix, Exim or another MTA with a DKIM signing component reads the private key from a file.
  • An application that signs its own mail, for example with a DKIM library.
  • Amazon SES with Bring Your Own DKIM (BYODKIM). SES accepts your own RSA key of 1024 to 2048 bits in PKCS#1 or PKCS#8 format. Paste the private key without the BEGIN/END lines and line breaks, and publish the public key as a TXT record at selector._domainkey.example.com with the value p= plus the key.
  • Any other sender whose setup guide asks you to supply a key pair.

Selector names and key rotation

The selector exists so a domain can publish several keys at once (RFC 6376, section 3.1). The RFC advises against reusing a selector for a new key: “A better strategy is to assign new keys to new selectors.” Practical naming rules:

  • Use letters, digits and hyphens. Dots are allowed, but each part becomes its own DNS label.
  • Encode the date (s202610) or the sender (crm2026), so you can tell keys apart in DNS and in the s= tag of the signature.
  • Use a different selector for each service that signs for your domain. Each one holds its own key.

M3AAWG’s DKIM key rotation best practices recommend rotating keys at least every six months. A rotation with this generator:

  1. Generate a new key pair with a new selector and publish its TXT record.
  2. Wait until the record resolves (check it with the DKIM checker), then switch your signer to the new private key and selector.
  3. Keep the old record published for at least seven days (M3AAWG suggests 7 to 30), so mail that was signed before the switch still verifies.
  4. Revoke the old key by publishing its record with an empty p= value. M3AAWG recommends this over deleting the record.

DKIM key size: 1024, 2048 or 4096 bits

RFC 8301 sets the rules: signers must use RSA keys of at least 1024 bits and should use at least 2048 bits; verifiers must handle keys from 1024 to 4096 bits and must not accept signatures made with smaller keys. The same RFC requires rsa-sha256 for signing; rsa-sha1 must not be used.

Key sizeTXT valueStrings of 255 charactersUse it when
1024 bits234 characters1Your DNS host can’t store a longer record.
2048 bits410 characters2Almost always.
4096 bits754 characters3You control the signer and DNS, and every service that needs the key accepts it. Amazon SES BYODKIM, for example, takes at most 2048 bits.

Character counts are for the record as the generator writes it, without t=y. RFC 6376 already pointed out that large keys “might not fit within a 512-byte DNS UDP response packet” (section 3.3.3). Google Workspace, Microsoft 365 and Amazon SES all offer 2048 bits as their largest size.

The p= value is the public key in SubjectPublicKeyInfo form, which is what openssl rsa -pubout writes and what DKIM records use in practice. RFC 6376 names the bare RSAPublicKey structure, but erratum 3017 (held for the next update of the RFC) notes that the RFC’s own example produces SubjectPublicKeyInfo and that most implementations accept such keys.

Ed25519 keys

RFC 8463 adds a second key type: k=ed25519 with the algorithm ed25519-sha256. Its public keys are much shorter: the p= value is the 32-byte key in base64. The RFC says verifiers must implement it, but RSA remains the type every verifier is required to support (RFC 6376), and RFC 8463 lets signers add a second signature with the new algorithm next to the old one. So if you use Ed25519, sign with an RSA key as well. This generator creates RSA keys only.

Test the DKIM record

DNS changes can take from a few minutes up to the record’s TTL, or the time your DNS provider states, to show up. Then:

  • Look up the key with the DKIM checker: enter your domain and selector to confirm the record parses and the key length is right. The link under the generated record fills both in.
  • Send a message to a mailbox you control and read the Authentication-Results header (dkim=pass with your domain) in the email header analyzer.

DKIM is one of three records receivers check. Pair it with an SPF record from the SPF record generator and a DMARC policy from the DMARC generator, so receivers know what to do with mail that fails. The guide to email deliverability shows how the three fit together.

Sources

Checked October 9, 2026: RFC 6376 and its errata; RFC 1035; RFC 8301; RFC 8463; Google Workspace: Set up DKIM; Microsoft: Set up DKIM to sign mail from your Microsoft 365 domain; Twilio SendGrid: DKIM records; Mailchimp: Set up email domain authentication; Amazon SES: Bring your own DKIM; GoDaddy: Add a TXT record; M3AAWG DKIM Key Rotation Best Common Practices (revised March 2019).

Frequently asked questions

How do I create a DKIM record?

Generate an RSA key pair, install the private key in the software that signs your outgoing mail, and publish the public key as a TXT record at selector._domainkey.yourdomain with the value v=DKIM1; k=rsa; p= followed by the key. The generator above does the first and last step. If your email provider creates DKIM keys for you, as Google Workspace and Microsoft 365 do, use its records instead.

What is a DKIM selector?

A name that lets one domain publish several DKIM keys at the same time (RFC 6376, section 3.1). The key lives at selector._domainkey.example.com, and every signature names its selector in the s= tag. Give each new key a new selector, for example one based on the date, so old and new keys can overlap while you switch.

Should I use a 1024 or 2048 bit DKIM key?

2048 bits. RFC 8301 requires at least 1024 bits and says signers should use at least 2048. Use 1024 only if your DNS host can't store the longer record, which is also Google's advice for Google Workspace.

How do I add a DKIM record in Office 365?

You don't paste a key into Microsoft 365. Microsoft generates the key pairs and you publish two CNAME records, selector1._domainkey and selector2._domainkey, with the values the Microsoft Defender portal shows for your domain. Microsoft says a TXT record with your own key isn't supported for Microsoft 365.

How do I add a DKIM record in GoDaddy?

In GoDaddy's DNS management, add a record, select TXT as the type, enter the selector part (for example s202610._domainkey) as the name without your domain, and paste the generated value. GoDaddy accepts TXT values of up to 1,024 characters, enough for a 2048-bit key.

Email validation API

Validate emails in your app

emailvalidation.io checks syntax, MX records and the mailbox over SMTP, flags disposable, role and free addresses and returns a quality score, in one request.

/v1/info Email validation API Read the documentation

100 free validations every month. No credit card required.

GET https://api.emailvalidation.io/v1/info?email=support@emailvalidation.io

{
  "email": "support@emailvalidation.io",
  "user": "support",
  "tag": "",
  "domain": "emailvalidation.io",
  "format_valid": true,
  "mx_found": true,
  "smtp_check": true,
  "catch_all": null,
  "role": true,
  "disposable": false,
  "free": false,
  "score": 0.64,
  "state": "deliverable",
  "reason": "valid_mailbox",
  "did_you_mean": ""
}

Free email tools

Start using our email validation software today!

Get 100 validations per month for free