FREE DKIM GENERATOR

DKIM generator

Create a DKIM key pair and the TXT record for your domain. Publish the public key in DNS, load the private key into your mail server, and start signing your mail.

Key length

Keys are generated in your browser. The private key is never sent to TrueEmailer or anyone else.

How to use the DKIM generator

Enter your domain and a selector, choose a 2048 bit key, and select Generate. You get two keys. The public key goes into DNS as a TXT record. The private key goes into your mail server, which uses it to sign outgoing mail. Google says DKIM can take up to 48 hours to start working after you add the record.

If you use Google Workspace, create the key in the Google Admin console instead. Google generates and manages it there.

Before you start

You need three things.

  • Access to the DNS settings of your domain, usually at your domain host.
  • Access to the mail server or sending service that will sign your mail, with a place to load a private key.
  • A selector name that no other DKIM key on your domain uses. To find the selector in use now, send a test message to yourself, view the message source, and read the s= value in the DKIM-Signature header.

Fill in the generator

FieldWhat to enterExample
Domain nameThe domain in your From addressexample.com
SelectorA short name for this key, lowercase letters and digitsmail1
Key length2048 if your DNS host accepts it, 1024 if it does not2048

Google recommends 2048 bit keys because longer keys are more secure. Choose 1024 only if your domain host does not support 2048.

Select Generate. The results screen shows three items.

ItemWhere it goes
DNS host name, for example mail1._domainkeyThe Host field of your TXT record
TXT record value, starting v=DKIM1; k=rsa; p=The Value field of your TXT record
Private keyYour mail server's signing settings

The private key appears once. Copy it before you leave the screen. Never publish it, email it or paste it into DNS.

Publish the public key

Add one TXT record at your DNS host with these values.

FieldValue
TypeTXT
Host, Name or AliasThe DNS host name from the generator
ValueThe TXT record value from the generator

Save the record. Some DNS hosts add your domain to the end of the host name for you. If yours does, enter only mail1._domainkey.

Each domain needs its own key. Google tells admins to get a unique key for every domain they set up.

Load the private key and turn on signing

Open your mail server or sending service and find its DKIM settings. Enter the domain, the same selector you chose in the generator, and the private key. Turn signing on.

The selector in the server must match the selector in the DNS host name. A mismatch is the most common reason a correct record still fails.

Check that it works

  1. Wait for the DNS change to spread. Google gives up to 48 hours.
  2. Send a message to a Gmail address that is not the address you sent from.
  3. Open the message, select More next to Reply, then select Show original.
  4. Find the Authentication-Results header and look for dkim=pass.

If the header has no DKIM line at all, your messages are not signed. Go back to the signing step.

Fix common DKIM problems

What you seeCauseFix
No DKIM line in Authentication-ResultsThe mail server is not signing.Confirm the private key is loaded and signing is turned on.
dkim is anything other than passThe selector in DKIM-Signature (s=) does not match the selector in the DNS host name.Use one selector in both places.
dkim is anything other than pass and the selector matchesThe public key was copied with extra spaces, line breaks or missing characters.Copy the TXT record value again, in one piece.
dkim is anything other than pass after you generated a second keyThe public key in DNS and the private key on the server come from different generator runs.Use the pair from one run. Replace both if you ran the generator twice.
The record was added within the last 48 hoursDNS has not finished updating.Test again after 48 hours.
DNS host rejects the valueSome hosts limit TXT record length.Read your host's help page on character limits, or generate a 1024 bit key. Google covers this in its DKIM troubleshooting guide.
Signing works until a footer is addedA gateway that edits messages can interfere with DKIM. Google tells admins to check this.Add footers before the message is signed, or turn the edit off.

Why TrueEmailer for deliverability

Receiving servers use your public key to check the signature on each message. Google requires SPF or DKIM from everyone who sends to personal Gmail accounts, and all three of SPF, DKIM, and DMARC from senders above 5,000 messages a day.

Doing DKIM by hand leaves room for the errors in the table above. A wrong selector or a mismatched key pair is easy to create and slow to find, because DNS changes take hours to confirm.

TrueEmailer removes that setup step.

  • SPF, DKIM, and DMARC are configured at setup, so signing is in place before the first send. Need SPF too? Use the free SPF record generator.
  • Mail leaves from pre-warmed SMTP infrastructure. See deliverability and warmup.

A passing DKIM check proves the owner of the domain signed a message. It does not give you a good reputation. Complaint rates, list quality, and message content still decide where mail lands, and no tool removes that work. Keep your list clean with the free email verifier.

DKIM generator FAQ

Do I need DKIM if I already have SPF?

+

Set up both. Google requires SPF or DKIM from every sender to personal Gmail accounts, and all three of SPF, DKIM and DMARC from bulk senders.

Which key length should I choose?

+

Choose 2048 if your DNS host accepts it. Google recommends it. Choose 1024 only when your host does not support 2048.

Can I use more than one selector?

+

Yes. Each key has its own selector and its own TXT record. Google tells admins to pick a different selector when the current one is already in use.

Can two domains share one key?

+

No. Google says each domain needs its own DKIM key.

How long until DKIM works?

+

Google says up to 48 hours after you add the record. Test again after that window before you change anything.

Is it safe to generate DKIM keys online?

+

This generator creates the key pair in your browser with the Web Crypto API. The private key is not sent to TrueEmailer or any other server.

Ready to get started?

Launch your first AI campaign in no time and unlock the full potential of the hundreds of emails you send daily.