Free DKIM Record Generator

Create a DKIM key pair and the exact DNS record to publish for it — right in your browser. Your private key is generated locally and never touches a server.

Generate a DKIM key pair

Creates an RSA key pair in your browser and the exact DNS TXT record to publish. No key material ever leaves this page.

Changes setup instructions only — never the generated key.

Letters, digits, dots, hyphens and underscores. If your provider requires a specific selector, use that one.

Key size

Marks the record as testing; some receivers ignore such signatures. Remove the flag before production use.

Publicly visible in DNS. Never put secrets here. Semicolons are removed; 100 characters max.

No key generated yet

Fill in the form and choose Generate key pair. Your keys are created locally in this browser and never uploaded.

Private by design: the key pair is generated with your browser's Web Crypto API. No input or key material is sent to, logged by, or stored on any server — you can even go offline after the page loads.

How the DKIM generator works

Enter your details

Pick your email provider for tailored setup steps, then enter your sending domain, a selector, key size, and optional flags. Everything stays in this browser tab.

Generate the key pair

Your browser creates an RSA key pair with the Web Crypto API (RSASSA-PKCS1-v1_5 with SHA-256, the modern DKIM standard). No server is involved.

Publish and configure

Copy the TXT record into your DNS provider, save the private key somewhere safe, and follow the provider-specific steps to start signing your mail.

What this tool does and does not do

  • This tool creates key material and a DNS record value. It does not configure your email provider or mail server to sign messages — that final step always happens with your sender.
  • Keys are RSA with SHA-256 only (rsa-sha256). Ed25519 generation is not supported yet, and SHA-1 is deliberately not offered because RFC 8301 prohibits it.
  • Many hosted providers (Google Workspace, Microsoft 365, SendGrid, Mailchimp) can generate and manage DKIM keys for you. When a provider offers its own flow, following it is usually simpler than bringing your own key.
  • Because nothing leaves your browser, we cannot recover a lost private key. If you lose it, publish a new record under a new selector and reconfigure your signer.
  • A published DKIM record only helps when your sender actually signs with the matching selector and domain — the record alone does not make mail pass DKIM, and DKIM alone does not guarantee inbox placement.

Related free tools

DKIM Record Checker

Verify a published DKIM record for any selector and domain, including key strength and revocation checks.

Open tool

SPF Record Generator

Build a valid SPF record for your sending sources, with lookup-count guidance and zone-file output.

Open tool

DMARC Record Generator

Create an RFC 9989 DMARC record with reporting addresses and rollout guidance.

Open tool

Frequently Asked Questions

What is a DKIM record?

A DKIM record is a DNS TXT record published at <selector>._domainkey.<your-domain>. It contains the public key that receiving mail servers use to verify the digital signature your sender adds to each message. A valid signature proves the message was authorized by the domain owner and was not altered in transit.

Is my private key safe when I use this generator?

Yes. The key pair is created by your browser using the Web Crypto API. Nothing — not the domain, selector, or either key — is ever sent to a SalesBlink server, logged, or stored. You can disconnect from the internet after the page loads and the generator still works. Keep the private key secret once you download it.

Which key size should I choose?

2048 bits is the right default: it is the size current DKIM guidance recommends and every major receiver supports. 4096 bits is stronger but produces a very long DNS record that some DNS providers handle poorly, and it costs more CPU per signature. 1024 bits is the RFC 8301 minimum and is only offered, behind a warning, for legacy systems that cannot handle a longer key.

What is a DKIM selector?

A selector is a short label that identifies which key signed a message, so a domain can run several keys at once (for example one per provider, or an old and new key during rotation). It appears in the DKIM-Signature header and becomes the first part of the DNS host name. If your provider mandates a selector, use theirs.

What does the testing flag (t=y) do?

It tells receivers you are still testing DKIM, and some receivers treat such signatures as less meaningful. It is useful while you verify that signing works end to end, but you should republish the record without the flag before relying on DKIM in production.

Does generating a key pair turn on DKIM signing?

No. This tool only creates the key pair and the record to publish. DKIM starts working only after you (1) publish the TXT record in DNS and (2) configure your email provider or mail server to sign outgoing mail with the matching private key and selector. Many hosted providers can manage keys for you — check their setup flow first.

Increase Your Sales Right Now

Automate Sales Outreach & Get Booked!

Start Free Trial

(14 Day Free Trial, No CC Required)