Skip to content
Free, runs in your browser

DKIM key generator

Make an RSA key pair for DKIM and the DNS record to publish. The key is generated in your browser and never sent to us.

Generate a key pair

Any name not already in use, e.g. dkim1.
Key length

Generated in your browser with WebCrypto. No request is made and nothing is sent to us.

Do you need to make your own key?

Usually not. Microsoft 365, Google Workspace and almost every email service make the key pair themselves, keep the private half, and give you a record (or a CNAME) to publish. Use theirs: a key you generate here only helps a server you run that signs email itself, such as Postfix with OpenDKIM, Exim or a self-hosted app.

Setting it up

  1. Generate the key and copy the private key to the signing server.
  2. Configure the server to sign as the domain with the selector you chose (OpenDKIM's KeyTable and SigningTable, for example).
  3. Publish the TXT record at selector._domainkey.yourdomain. If your DNS host asks for strings of 255 characters or fewer, use the split version.
  4. Check it with the DKIM checker, then send an email to the free email test to confirm the signature verifies.

Key length

2048-bit RSA is the standard. Some older DNS control panels cut off long TXT values, which is the only good reason to choose 1024-bit; switch DNS host before settling for a weak key.

The easier route

With hosted DKIM, a client's _domainkey records live with Domain Health Hub: you add each service's keys without waiting for a DNS login, and every key is checked daily. See features.

Do this for every client, every day

  • All nine checks on every client domain, daily, graded A to F
  • Alerts by email or webhook when a grade drops or a record changes
  • A monthly report card for each client, with your logo on it
  • Hosted DMARC, SPF, DKIM and MTA-STS, so fixes don't wait for a DNS login

Start a free 28-day trial: up to 3 domains, no card needed.

Questions

Is the private key sent to you?

No. It's generated by your browser's WebCrypto and never leaves the page. Reload and it's gone, so copy it first.

Should I use 2048 or 1024 bits?

2048. Choose 1024 only if your DNS host can't publish the longer record, and plan to move.

What format is the private key?

PKCS#8 PEM (BEGIN PRIVATE KEY), which OpenDKIM, Exim, Postfix milters and most libraries read.

I use Microsoft 365 or Google Workspace. Do I need this?

No. Turn on DKIM in their admin centre: they make the key and show you the records to publish.

How often should I rotate DKIM keys?

Every six to twelve months is common. Publish the new key under a new selector, switch signing over, then remove the old record.

Check every DKIM key, every day.

Start a free 28-day trial: up to 3 domains, no card needed.