DKIM key generator
Make an RSA key pair for DKIM and the DNS record to publish. The key is generated in your browser and never sent to us.
Generate a key pair
Generated in your browser with WebCrypto. No request is made and nothing is sent to us.
Do you need to make your own key?
Usually not. Microsoft 365, Google Workspace and almost every email service make the key pair themselves, keep the private half, and give you a record (or a CNAME) to publish. Use theirs: a key you generate here only helps a server you run that signs email itself, such as Postfix with OpenDKIM, Exim or a self-hosted app.
Setting it up
- Generate the key and copy the private key to the signing server.
- Configure the server to sign as the domain with the selector you chose (OpenDKIM's
KeyTableandSigningTable, for example). - Publish the TXT record at
selector._domainkey.yourdomain. If your DNS host asks for strings of 255 characters or fewer, use the split version. - Check it with the DKIM checker, then send an email to the free email test to confirm the signature verifies.
Key length
2048-bit RSA is the standard. Some older DNS control panels cut off long TXT values, which is the only good reason to choose 1024-bit; switch DNS host before settling for a weak key.
The easier route
With hosted DKIM, a client's _domainkey records live with Domain Health Hub: you add each service's keys without waiting for a DNS login, and every key is checked daily. See features.
Do this for every client, every day
- All nine checks on every client domain, daily, graded A to F
- Alerts by email or webhook when a grade drops or a record changes
- A monthly report card for each client, with your logo on it
- Hosted DMARC, SPF, DKIM and MTA-STS, so fixes don't wait for a DNS login
Start a free 28-day trial: up to 3 domains, no card needed.
Keep going
- DKIM explained: keys, selectors and rotationThe guide
- DKIM not foundHow to fix it
- Weak DKIM keyHow to fix it
- Broken DKIM keyHow to fix it
- DKIM checkerFind a domain's DKIM keys, with or without the selector, and check their size.
- Email header analyserPaste an email's headers to see its route, SPF, DKIM and DMARC results and alignment.
- DMARC checkerSee a domain's DMARC policy in plain English, and where its reports go.
- Free domain checkerAll nine checks on a domain, with a grade from A to F.
- Report cardsWhat your clients get each month, with your logo on it.
Questions
Is the private key sent to you?
No. It's generated by your browser's WebCrypto and never leaves the page. Reload and it's gone, so copy it first.
Should I use 2048 or 1024 bits?
2048. Choose 1024 only if your DNS host can't publish the longer record, and plan to move.
What format is the private key?
PKCS#8 PEM (BEGIN PRIVATE KEY), which OpenDKIM, Exim, Postfix milters and most libraries read.
I use Microsoft 365 or Google Workspace. Do I need this?
No. Turn on DKIM in their admin centre: they make the key and show you the records to publish.
How often should I rotate DKIM keys?
Every six to twelve months is common. Publish the new key under a new selector, switch signing over, then remove the old record.
Check every DKIM key, every day.
Start a free 28-day trial: up to 3 domains, no card needed.