Free DKIM Record Generator - Create DKIM DNS Records
DKIM (DomainKeys Identified Mail) adds a cryptographic signature to outgoing emails so receivers can verify the message was sent by your domain and was not altered in transit. Our free DKIM record generator helps you create the DNS TXT record that publishes your DKIM public key. Configure your selector name, choose RSA or Ed25519 key type, paste your public key, and get a properly formatted record ready to add to your DNS.
What This Tool Checks
Comprehensive analysis powered by Vysiro's scanning engines
Custom DKIM selector name configuration
Key type selection (RSA-2048, RSA-4096, Ed25519)
Public key paste and validation
Proper record formatting with tag syntax
Key length verification and recommendations
Testing flag support for staging rollout
Granularity control (g= tag)
Copy-paste ready DNS TXT record output
How It Works
Get results in seconds with our automated scanning process
Enter a DKIM selector name (e.g., 'google', 'selector1', or a custom name)
Choose your key type: RSA-2048 (recommended), RSA-4096, or Ed25519
Paste your DKIM public key (base64-encoded, from your email provider or key pair)
Optionally enable the testing flag (t=y) for staged rollout
Review the generated DKIM TXT record with all tags properly formatted
Add the record to your DNS at selector._domainkey.yourdomain.com
Frequently Asked Questions
Everything you need to know about dkim record generator
What is a DKIM record?
A DKIM record is a DNS TXT record published at selector._domainkey.yourdomain.com that contains your public key. When you send email, your mail server signs the message with the private key. Receivers look up the public key in DNS to verify the signature and confirm the email is authentic.
How do I choose a DKIM selector name?
A selector is a label that identifies which key to use for verification. Your email provider usually assigns one (e.g., Google uses 'google', Microsoft uses 'selector1'). For custom setups, use descriptive names like 'mail2024' or 'primary'. Include a date or version to simplify key rotation.
Should I use RSA or Ed25519 for DKIM?
RSA-2048 is the most widely supported and recommended choice. Ed25519 offers smaller keys and faster verification but has limited support among receivers. For maximum compatibility, use RSA-2048. Some organizations publish both RSA and Ed25519 keys with different selectors.
Where do I get my DKIM public key?
Your email provider generates the DKIM key pair. In Google Workspace, go to Admin > Apps > Gmail > Authenticate email. In Microsoft 365, go to Defender > Email authentication > DKIM. For custom mail servers, generate a key pair using openssl and configure your MTA with the private key.
What is the DKIM testing flag (t=y)?
The t=y flag tells receivers that DKIM is in testing mode and failures should not cause message rejection. Use this flag during initial deployment to catch configuration issues without affecting delivery. Remove it once you confirm signing is working correctly.
How often should I rotate DKIM keys?
Rotate DKIM keys every 6 to 12 months as a security best practice. Use a new selector for each rotation so old signatures remain verifiable during the transition. Vysiro recommends publishing the new key 24-48 hours before switching your signer to allow the DNS to update.
Related Free Tools
Continue your domain security analysis
DKIM Verifier
Check DKIM key existence, configuration, and selector validation.
Use toolDMARC Generator
Build DMARC TXT records with policy selection, reporting, and alignment configuration.
Use toolSPF Generator
Build SPF TXT records with a visual mechanism builder, lookup counter, and validation.
Use toolTrustScore
Get an instant composite trust score (0-1000) across 29 security categories.
Use toolGo Beyond Free Checks
Get continuous monitoring, automated fixes, proof packs, and API access. Protect your domains with Vysiro's agentless attack-surface monitor.