Where do I get the key for a cold email DKIM record?
From the service that sends your mail. Google Workspace generates it under Apps, Gmail, Authenticate email; Microsoft 365 publishes it as two CNAME records instead of a TXT record, so it does not need this tool. Only the public key goes in DNS. The private key stays with the mail host, and this page refuses to build a record from one.
What is the selector in a cold email DKIM record?
A label that lets one domain publish several keys. The record lives at selector._domainkey.yourdomain.com, and every signed email names its selector in the s= tag of its DKIM-Signature header, so receivers know which key to fetch. Your mail host chooses it; Google Workspace uses google by default. Our guide to what DKIM is shows how to find it in a sent email.
Should a cold email domain use a 1024-bit or 2048-bit DKIM key?
2048-bit. RFC 8301 requires at least 1024 bits and recommends 2048, and receivers still accept 1024-bit keys, so an older key is not an emergency. A 2048-bit record is longer than 255 characters, which is normal: most DNS panels split it into two strings automatically.
How do I check the cold email DKIM record is live?
Run the domain checker and enter your selector. Then send yourself an email and look for dkim=pass in the Authentication-Results header. DNS changes can take up to a few hours to show everywhere.