Menu

DKIM record generator: turn a public key into a DNS record

Paste the DKIM public key your mail host gave you, add the selector, and get the exact TXT record and host name to publish. It runs in your browser, so the key is never uploaded.
Key type
TypeTXT
Host / nameselector._domainkeyMany DNS panels add the domain for you, so enter just selector._domainkey.
ValueFix the issue below to see your record.

A selector is letters, numbers, dots and dashes, such as "s1" or "google".

Paste the public key your mail host or key generator gave you.

Published it? Run the domain checker to confirm it resolves.

Where do I get the key for a cold email DKIM record?

From the service that sends your mail. Google Workspace generates it under Apps, Gmail, Authenticate email; Microsoft 365 publishes it as two CNAME records instead of a TXT record, so it does not need this tool. Only the public key goes in DNS. The private key stays with the mail host, and this page refuses to build a record from one.

What is the selector in a cold email DKIM record?

A label that lets one domain publish several keys. The record lives at selector._domainkey.yourdomain.com, and every signed email names its selector in the s= tag of its DKIM-Signature header, so receivers know which key to fetch. Your mail host chooses it; Google Workspace uses google by default. Our guide to what DKIM is shows how to find it in a sent email.

Should a cold email domain use a 1024-bit or 2048-bit DKIM key?

2048-bit. RFC 8301 requires at least 1024 bits and recommends 2048, and receivers still accept 1024-bit keys, so an older key is not an emergency. A 2048-bit record is longer than 255 characters, which is normal: most DNS panels split it into two strings automatically.

How do I check the cold email DKIM record is live?

Run the domain checker and enter your selector. Then send yourself an email and look for dkim=pass in the Authentication-Results header. DNS changes can take up to a few hours to show everywhere.