Create a DKIM key pair and the exact DNS record to publish for it — right in your browser. Your private key is generated locally and never touches a server.
Creates an RSA key pair in your browser and the exact DNS TXT record to publish. No key material ever leaves this page.
No key generated yet
Fill in the form and choose Generate key pair. Your keys are created locally in this browser and never uploaded.
Private by design: the key pair is generated with your browser's Web Crypto API. No input or key material is sent to, logged by, or stored on any server — you can even go offline after the page loads.
Pick your email provider for tailored setup steps, then enter your sending domain, a selector, key size, and optional flags. Everything stays in this browser tab.
Your browser creates an RSA key pair with the Web Crypto API (RSASSA-PKCS1-v1_5 with SHA-256, the modern DKIM standard). No server is involved.
Copy the TXT record into your DNS provider, save the private key somewhere safe, and follow the provider-specific steps to start signing your mail.
Verify a published DKIM record for any selector and domain, including key strength and revocation checks.
Open toolBuild a valid SPF record for your sending sources, with lookup-count guidance and zone-file output.
Open toolCreate an RFC 9989 DMARC record with reporting addresses and rollout guidance.
Open toolA DKIM record is a DNS TXT record published at <selector>._domainkey.<your-domain>. It contains the public key that receiving mail servers use to verify the digital signature your sender adds to each message. A valid signature proves the message was authorized by the domain owner and was not altered in transit.
Yes. The key pair is created by your browser using the Web Crypto API. Nothing — not the domain, selector, or either key — is ever sent to a SalesBlink server, logged, or stored. You can disconnect from the internet after the page loads and the generator still works. Keep the private key secret once you download it.
2048 bits is the right default: it is the size current DKIM guidance recommends and every major receiver supports. 4096 bits is stronger but produces a very long DNS record that some DNS providers handle poorly, and it costs more CPU per signature. 1024 bits is the RFC 8301 minimum and is only offered, behind a warning, for legacy systems that cannot handle a longer key.
A selector is a short label that identifies which key signed a message, so a domain can run several keys at once (for example one per provider, or an old and new key during rotation). It appears in the DKIM-Signature header and becomes the first part of the DNS host name. If your provider mandates a selector, use theirs.
It tells receivers you are still testing DKIM, and some receivers treat such signatures as less meaningful. It is useful while you verify that signing works end to end, but you should republish the record without the flag before relying on DKIM in production.
No. This tool only creates the key pair and the record to publish. DKIM starts working only after you (1) publish the TXT record in DNS and (2) configure your email provider or mail server to sign outgoing mail with the matching private key and selector. Many hosted providers can manage keys for you — check their setup flow first.
Automate Sales Outreach & Get Booked!
Start Free Trial(14 Day Free Trial, No CC Required)