Free Tool · Runs in your browser

DKIM Record Generator

Generate an RSA key pair with the Web Crypto API entirely on your device, get the public-key TXT record for selector._domainkey and download the private key for your mail server. Nothing is sent to us.

  • 100% free
  • No signup
  • Nothing leaves your browser

DKIM Record Generator

A short label that becomes part of the DNS name. Use a new one for each key so you can rotate without downtime.

Only used to show the full DNS name and to name the downloaded key.

2048-bit is the current standard and what Gmail and Microsoft recommend. Only pick 1024 if your DNS host cannot store long TXT values.

DNS name preview: io1._domainkey.yourdomain.com

Who this is for

Google Workspace and Microsoft 365 create their own DKIM keys inside the admin console, so you do not need this tool for them. Use it for self-hosted SMTP (Postfix with OpenDKIM or rspamd, Exim, Haraka), Amazon SES BYODKIM, or any provider that lets you upload your own private key.

Your DKIM record appears here

Click Generate key pair. Your browser creates the RSA keys locally with the Web Crypto API; nothing is uploaded.

How It Works

Three steps, no account needed

  1. 1

    Pick a selector and key size

    Enter a short selector such as io1 and keep 2048-bit RSA. The selector becomes part of the DNS name, so use a new one when you rotate keys.

  2. 2

    Generate in your browser

    The Web Crypto API creates the key pair on your device. The public key becomes a TXT record, the private key a PEM file you download.

  3. 3

    Publish and install

    Add the TXT record at selector._domainkey, install the private key on your mail server, send a test and confirm dkim=pass with the DKIM checker.

Record & Asset Generators

How DKIM signing works

DKIM (DomainKeys Identified Mail) adds a cryptographic signature to every outgoing message. Your mail server signs selected headers and the body with a private key; receivers fetch the matching public key from DNS at selector._domainkey.yourdomain.com and verify the signature. A valid signature proves the message was not altered in transit and that whoever signed it controls your DNS.

The DNS record holds three tags: the version, the key type and the base64 public key.

io1._domainkey.yourdomain.com. IN TXT "v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA..."

Who needs to generate their own keys

Hosted mailbox providers generate and manage DKIM keys for you. In Google Workspace you turn it on under Apps, Gmail, Authenticate email; in Microsoft 365 under Defender, Email authentication, DKIM. You only need this generator when you control the signing side yourself.

  • Self-hosted SMTP with Postfix and OpenDKIM or rspamd, Exim, Haraka or similar.
  • Amazon SES with Bring Your Own DKIM, which accepts a private key you supply.
  • Any transactional provider that offers custom key upload rather than a CNAME.
  • Testing and lab setups where you want a throwaway key without installing OpenSSL.

2048-bit keys and the 255-character split

Gmail, Yahoo and Microsoft all recommend 2048-bit keys, and 1024-bit keys are considered weak. The trade-off is length: a 2048-bit public key produces a TXT value of over 400 characters, while a single DNS TXT string is limited to 255. Most DNS hosts split the value into multiple quoted strings automatically. If yours rejects it, use the split form the tool shows, which resolvers concatenate on lookup.

Some older DNS panels have a hard limit that only fits 1024-bit keys. Moving DNS to a modern provider is a better fix than downgrading the key.

Installing the private key and rotating later

Save the PEM file on the sending server with permissions restricted to the mail daemon, and point your signing software at it with the same selector and domain used in DNS. Send a test to a Gmail address and inspect the headers for dkim=pass and the d= value matching your domain. Then confirm the record with the DKIM checker.

Rotate keys periodically by generating a new pair under a new selector, publishing it, switching the server, and only then deleting the old record. Cold email operators who would rather not manage servers can let InboxOne provision mailboxes with DKIM, SPF and DMARC already configured.

FAQ

Frequently asked questions

Still stuck? Book a 30-minute deliverability call and we'll look at your setup together.

Use this generator: choose a selector and key size and click Generate. Your browser creates an RSA key pair with the Web Crypto API. Publish the public key as a TXT record at selector._domainkey.yourdomain.com and install the private key PEM on the server that signs your mail.

The selector is a label that lets a domain publish several DKIM keys at once. It appears in the s= tag of each signature and forms the DNS name selector._domainkey.yourdomain.com. Any short alphanumeric string works. Use a new selector each time you rotate keys so old and new can coexist.

Use 2048-bit. It is what Gmail, Yahoo and Microsoft recommend, and 1024-bit keys are treated as weak by some receivers. The only reason to choose 1024 is a DNS host that cannot store a TXT value longer than 255 characters, and even then changing DNS provider is the better fix.

No. The key pair is generated inside your browser using the Web Crypto API and only exists in the page memory until you copy or download it. Nothing is transmitted to InboxOne or any third party. Refreshing the page discards it, so download the PEM before you leave.

No. Both generate and manage their own DKIM keys. In Google Workspace enable DKIM under Apps, Gmail, Authenticate email and publish the record it gives you. In Microsoft 365 enable it in the Defender portal and add the two CNAME records. Use this tool for self-hosted SMTP or providers that accept a custom key.

Send a message to a Gmail account, open Show original and look for dkim=pass with d= set to your domain. Then run the DKIM checker with your selector to confirm the public key is published correctly and long enough. If the record is missing, wait for DNS propagation and retry.

Ready to Scale Your Outbound?

Your Cold Email Infrastructure Shouldn't Be the Bottleneck.

Domains, mailboxes, DNS, deliverability, and platform exports — all from one dashboard. Starting at $39/month for 10 production-ready mailboxes.

Inbox One Logo

Cold email infrastructure platform. Buy domains, provision Google Workspace mailboxes, auto-configure DNS, and export to 5 outreach platforms — all from one dashboard.

© 2026 InboxOne. All rights reserved.