🔑 DKIM Record Builder

Paste your DKIM public key (the base64 body from your key pair, without headers/footers) and a selector to build the DNS TXT record. Publish it at selector._domainkey.yourdomain.com.

How the record is built

Nothing is looked up and nothing leaves your browser - this page does no DNS query and never sees your key on a server. It strips every space and line break out of the key box, then joins three tags in order:

Host:  <selector>._domainkey.yourdomain.com
Value: v=DKIM1; k=rsa; p=<base64 public key>

default._domainkey.example.com
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC7...

Because whitespace is removed, a key pasted across several lines works fine. The headers do not: -----BEGIN PUBLIC KEY----- would be glued straight into the p= value. Paste the base64 body only. Both boxes must be non-empty or the tool refuses to build.

Publishing it without breaking the key

A syntactically correct record does not mean mail will verify. The published public key must be the exact pair of the private key doing the signing, and a stray character anywhere in the base64 breaks verification silently.

Frequently asked questions

What selector name should I use?

Any label you like, as long as your signing software stamps the same one into the s= tag. Dated names such as mar2026 make rotation easy, since you can publish the next key at a fresh selector and switch over.

Can I put two DKIM keys on one domain?

Yes, at different selectors. That is how rotation and multiple sending platforms work. What you cannot do is publish two TXT records at the same selector._domainkey name - receivers may pick either one.

Do I need the k=rsa tag?

Not strictly; RSA is the default when it is absent. This builder writes it out anyway because an explicit tag is easier to read and to change later.