🔑 DKIM Record Builder
Paste your DKIM public key (the base64 body from your key pair, without headers/footers) and
a selector to build the DNS TXT record. Publish it at selector._domainkey.yourdomain.com.
How the record is built
Nothing is looked up and nothing leaves your browser - this page does no DNS query and never sees your key on a server. It strips every space and line break out of the key box, then joins three tags in order:
Host: <selector>._domainkey.yourdomain.com
Value: v=DKIM1; k=rsa; p=<base64 public key>
default._domainkey.example.com
v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC7...
Because whitespace is removed, a key pasted across several lines works fine. The
headers do not: -----BEGIN PUBLIC KEY----- would be glued straight into
the p= value. Paste the base64 body only. Both boxes must be non-empty or
the tool refuses to build.
Publishing it without breaking the key
- The private key never appears here. Only the public half goes into DNS. The private key stays on the machine that signs your mail.
- A single DNS string caps at 255 characters. A 2048-bit key's
p=value runs past 390 characters, so the record has to be split into several quoted chunks that the resolver rejoins. Most DNS panels do this for you; if yours does not, split it yourself and add no spaces between the pieces. - Replace
yourdomain.com. The host line is a template. Use your real domain, and put the record on the domain that appears in thed=tag of your signatures.
Frequently asked questions
What selector name should I use?
Any label you like, as long as your signing software stamps the same one into the
s= tag. Dated names such as mar2026 make rotation easy,
since you can publish the next key at a fresh selector and switch over.
Can I put two DKIM keys on one domain?
Yes, at different selectors. That is how rotation and multiple sending platforms
work. What you cannot do is publish two TXT records at the same
selector._domainkey name - receivers may pick either one.
Do I need the k=rsa tag?
Not strictly; RSA is the default when it is absent. This builder writes it out anyway because an explicit tag is easier to read and to change later.