Free DKIM Key Generator
For a self-hosted mail server. If you send through Google Workspace, Microsoft 365, or another managed provider, DKIM is set up in that provider's admin console instead — they generate and manage the keypair for you.
How to Use the DKIM Generator
Choose a selector
A short name (letters, numbers, hyphens) that identifies this key in DNS – "default" works if you don't need multiple keys.
Generate the keypair
ActiScan creates a real RSA-2048 keypair on the server and returns both halves immediately.
Publish and save
Copy the DNS record into your DNS host, and save the private key into your mail server's DKIM signing config – it's shown once.
What the Output Means
DNS recordPublishThe public key, formatted as v=DKIM1; k=rsa; p=<key>. Safe to publish – it only lets receivers verify signatures, not create them. Goes in a TXT record at <selector>._domainkey.yourdomain.com.
Private keySecretThe PEM-encoded private half. It goes into your mail server's DKIM signing configuration, never into DNS. It isn't stored anywhere after this page returns it – save it now.
SelectorLabelThe name you chose. It must match exactly between your mail server's signing config and the DNS record name – a mismatch means signatures reference a public key that doesn't exist.
How DKIM Key Generation Actually Works
Unlike SPF or DMARC records, which are just formatted text strings, DKIM needs an actual public/private keypair. This generator creates a real RSA-2048 keypair on ActiScan's server using Node's built-in crypto module – no key is faked or templated. The public half is reformatted as a DNS TXT record; the private half is returned to you as a standard PEM-encoded key, exactly what mail server software (Postfix + OpenDKIM, Exim, etc.) expects in its signing configuration.
Generation happens through a form submission handled by a server action, not a shareable GET link – so the private key is never exposed in a URL, browser history, or server log the way a query-string parameter would be. It also isn't persisted anywhere after the response is returned to your browser, which is exactly why you need to copy it before navigating away.
Generated Record Fields
| Tag | What it does | Example |
|---|---|---|
| v | Protocol version, always set by the generator. | v=DKIM1 |
| k | Key type – this generator always produces RSA. | k=rsa |
| p | The RSA-2048 public key, base64-encoded, stripped of PEM headers and line breaks. | p=MIGfMA0GCSq... |
Publishing Your DKIM Record
In your DNS host, create a new TXT record. The name is <selector>._domainkey.yourdomain.com (using the selector you chose above), and the value is the full DNS record the generator returned.
A 2048-bit RSA public key, base64-encoded, comes out well over 255 characters – longer than a single DNS TXT string is allowed to be. Most DNS hosts split a long TXT value into multiple quoted strings for you automatically; a few require you to do it manually. Check your record after publishing (below) if you're not sure it saved correctly.
How to Verify What You Published
Using nslookup
nslookup -type=TXT default._domainkey.yourdomain.com
Using dig
dig TXT default._domainkey.yourdomain.com
Replace default with your actual selector. Or skip the manual lookup and run it through the checker instead:
Next Steps
Verify what you published
DNS changes can take a few hours to propagate. Once it's live, confirm ActiScan – and everyone else – can actually see it.
DKIM Checker →On a managed platform instead?
Google Workspace, Microsoft 365, and most managed providers generate and manage their own DKIM keypair – you won't need this generator at all. Check your provider's admin console.
Want ongoing monitoring?
ActiScan scans on a schedule and alerts you if a DKIM key goes missing or a new sending platform shows up unprotected – across every domain you manage.
Start free →Frequently Asked Questions
Is this DKIM generator free?
Yes – generate a real DKIM keypair for free, no signup required.
Is the private key stored anywhere?
No. It's generated on the server for this one request and returned to your browser – ActiScan doesn't save a copy. If you navigate away without copying it, you'll need to generate a new keypair.
What key size does this generate?
RSA-2048. It's the current standard: strong enough for DKIM signing, and small enough to fit comfortably in a DNS TXT record. 1024-bit keys are considered weak and increasingly rejected by receiving servers.
Do I need this if I use Google Workspace or Microsoft 365?
No. Those providers (and most managed email platforms) generate and manage their own DKIM keypair in their admin console – this generator is for a self-hosted mail server where nobody's doing that for you.
What selector should I use?
Any label works – "default" is common. If you ever rotate keys, generate a new keypair under a different selector, publish it alongside the old one, switch your mail server to sign with it, then remove the old selector's DNS record once you're confident the new key is working.