How to use the DKIM generator
Enter your domain and a selector, choose a 2048 bit key, and select Generate. You get two keys. The public key goes into DNS as a TXT record. The private key goes into your mail server, which uses it to sign outgoing mail. Google says DKIM can take up to 48 hours to start working after you add the record.
If you use Google Workspace, create the key in the Google Admin console instead. Google generates and manages it there.
Before you start
You need three things.
- Access to the DNS settings of your domain, usually at your domain host.
- Access to the mail server or sending service that will sign your mail, with a place to load a private key.
- A selector name that no other DKIM key on your domain uses. To find the selector in use now, send a test message to yourself, view the message source, and read the
s=value in the DKIM-Signature header.
Fill in the generator
| Field | What to enter | Example |
|---|---|---|
| Domain name | The domain in your From address | example.com |
| Selector | A short name for this key, lowercase letters and digits | mail1 |
| Key length | 2048 if your DNS host accepts it, 1024 if it does not | 2048 |
Google recommends 2048 bit keys because longer keys are more secure. Choose 1024 only if your domain host does not support 2048.
Select Generate. The results screen shows three items.
| Item | Where it goes |
|---|---|
DNS host name, for example mail1._domainkey | The Host field of your TXT record |
TXT record value, starting v=DKIM1; k=rsa; p= | The Value field of your TXT record |
| Private key | Your mail server's signing settings |
The private key appears once. Copy it before you leave the screen. Never publish it, email it or paste it into DNS.
Publish the public key
Add one TXT record at your DNS host with these values.
| Field | Value |
|---|---|
| Type | TXT |
| Host, Name or Alias | The DNS host name from the generator |
| Value | The TXT record value from the generator |
Save the record. Some DNS hosts add your domain to the end of the host name for you. If yours does, enter only mail1._domainkey.
Each domain needs its own key. Google tells admins to get a unique key for every domain they set up.
Load the private key and turn on signing
Open your mail server or sending service and find its DKIM settings. Enter the domain, the same selector you chose in the generator, and the private key. Turn signing on.
The selector in the server must match the selector in the DNS host name. A mismatch is the most common reason a correct record still fails.
Check that it works
- Wait for the DNS change to spread. Google gives up to 48 hours.
- Send a message to a Gmail address that is not the address you sent from.
- Open the message, select More next to Reply, then select Show original.
- Find the Authentication-Results header and look for
dkim=pass.
If the header has no DKIM line at all, your messages are not signed. Go back to the signing step.
Fix common DKIM problems
| What you see | Cause | Fix |
|---|---|---|
| No DKIM line in Authentication-Results | The mail server is not signing. | Confirm the private key is loaded and signing is turned on. |
| dkim is anything other than pass | The selector in DKIM-Signature (s=) does not match the selector in the DNS host name. | Use one selector in both places. |
| dkim is anything other than pass and the selector matches | The public key was copied with extra spaces, line breaks or missing characters. | Copy the TXT record value again, in one piece. |
| dkim is anything other than pass after you generated a second key | The public key in DNS and the private key on the server come from different generator runs. | Use the pair from one run. Replace both if you ran the generator twice. |
| The record was added within the last 48 hours | DNS has not finished updating. | Test again after 48 hours. |
| DNS host rejects the value | Some hosts limit TXT record length. | Read your host's help page on character limits, or generate a 1024 bit key. Google covers this in its DKIM troubleshooting guide. |
| Signing works until a footer is added | A gateway that edits messages can interfere with DKIM. Google tells admins to check this. | Add footers before the message is signed, or turn the edit off. |
Why TrueEmailer for deliverability
Receiving servers use your public key to check the signature on each message. Google requires SPF or DKIM from everyone who sends to personal Gmail accounts, and all three of SPF, DKIM, and DMARC from senders above 5,000 messages a day.
Doing DKIM by hand leaves room for the errors in the table above. A wrong selector or a mismatched key pair is easy to create and slow to find, because DNS changes take hours to confirm.
TrueEmailer removes that setup step.
- SPF, DKIM, and DMARC are configured at setup, so signing is in place before the first send. Need SPF too? Use the free SPF record generator.
- Mail leaves from pre-warmed SMTP infrastructure. See deliverability and warmup.
A passing DKIM check proves the owner of the domain signed a message. It does not give you a good reputation. Complaint rates, list quality, and message content still decide where mail lands, and no tool removes that work. Keep your list clean with the free email verifier.
DKIM generator FAQ
Do I need DKIM if I already have SPF?
+
Set up both. Google requires SPF or DKIM from every sender to personal Gmail accounts, and all three of SPF, DKIM and DMARC from bulk senders.
Which key length should I choose?
+
Choose 2048 if your DNS host accepts it. Google recommends it. Choose 1024 only when your host does not support 2048.
Can I use more than one selector?
+
Yes. Each key has its own selector and its own TXT record. Google tells admins to pick a different selector when the current one is already in use.
Can two domains share one key?
+
No. Google says each domain needs its own DKIM key.
How long until DKIM works?
+
Google says up to 48 hours after you add the record. Test again after that window before you change anything.
Is it safe to generate DKIM keys online?
+
This generator creates the key pair in your browser with the Web Crypto API. The private key is not sent to TrueEmailer or any other server.