How DKIM signing works
DKIM (DomainKeys Identified Mail) adds a cryptographic signature to every outgoing message. Your mail server signs selected headers and the body with a private key; receivers fetch the matching public key from DNS at selector._domainkey.yourdomain.com and verify the signature. A valid signature proves the message was not altered in transit and that whoever signed it controls your DNS.
The DNS record holds three tags: the version, the key type and the base64 public key.
io1._domainkey.yourdomain.com. IN TXT "v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA..."Who needs to generate their own keys
Hosted mailbox providers generate and manage DKIM keys for you. In Google Workspace you turn it on under Apps, Gmail, Authenticate email; in Microsoft 365 under Defender, Email authentication, DKIM. You only need this generator when you control the signing side yourself.
- Self-hosted SMTP with Postfix and OpenDKIM or rspamd, Exim, Haraka or similar.
- Amazon SES with Bring Your Own DKIM, which accepts a private key you supply.
- Any transactional provider that offers custom key upload rather than a CNAME.
- Testing and lab setups where you want a throwaway key without installing OpenSSL.
2048-bit keys and the 255-character split
Gmail, Yahoo and Microsoft all recommend 2048-bit keys, and 1024-bit keys are considered weak. The trade-off is length: a 2048-bit public key produces a TXT value of over 400 characters, while a single DNS TXT string is limited to 255. Most DNS hosts split the value into multiple quoted strings automatically. If yours rejects it, use the split form the tool shows, which resolvers concatenate on lookup.
Some older DNS panels have a hard limit that only fits 1024-bit keys. Moving DNS to a modern provider is a better fix than downgrading the key.
Installing the private key and rotating later
Save the PEM file on the sending server with permissions restricted to the mail daemon, and point your signing software at it with the same selector and domain used in DNS. Send a test to a Gmail address and inspect the headers for dkim=pass and the d= value matching your domain. Then confirm the record with the DKIM checker.
Rotate keys periodically by generating a new pair under a new selector, publishing it, switching the server, and only then deleting the old record. Cold email operators who would rather not manage servers can let InboxOne provision mailboxes with DKIM, SPF and DMARC already configured.

