# Split a 2048-bit DKIM TXT Record Over 255 Characters

Source: https://srvscripts.com/guides/split-dkim-txt-record/
Updated: 2026-10-06
Publisher: srvScripts (https://srvscripts.com/)

**Short answer:** A single string inside a DNS TXT record can hold at most 255 characters, and a 2048-bit DKIM record is about 410. Store it as one TXT record made of several quoted strings, for example `"v=DKIM1; k=rsa; p=MIIB...(first 255)" "...rest"`. Receivers join the strings with no space added. Cloudflare splits long values for you, cPanel writes its own DKIM records already split, and in a BIND zone file you write the strings yourself inside parentheses. Never create two separate TXT records for one key.

We ran the BIND zone tests and the cPanel record checks below on our lab server (AlmaLinux 9.8, cPanel & WHM 11.138, BIND 9.16) on 6 October 2026, using a throwaway test key in a test zone, not a live domain. Cloudflare behaviour was checked against Cloudflare’s DNS documentation the same day.

## Why 2048-bit keys need splitting

DNS stores TXT data as “character-strings”, each with a length byte, so one string cannot be longer than 255 characters. A TXT record may hold several strings. For DKIM, RFC 6376 says the strings “MUST be concatenated together before use with no intervening whitespace”. So the split is invisible to receivers as long as all parts are in the same record.

Numbers from our lab: the public key of a 2048-bit RSA key is 392 base64 characters, and with `v=DKIM1; k=rsa; p=` in front the record is 410 characters. That is two strings: 255 + 155. A 1024-bit key fits in one string, which is why the problem appears when you upgrade to 2048 bits (the size Google recommends).

| Right | Wrong |
| --- | --- |
| One TXT record with two quoted strings | Two separate TXT records at the same name (RFC 6376 says results are then undefined) |
| Split anywhere, nothing added or removed | A quote character, backslash or an extra p= pasted into the value |
| Each string 255 characters or less | One unsplit 410-character string in a zone file (BIND refuses it) |

DKIM is forgiving about whitespace: RFC 6376 allows spaces inside the base64 `p=` value. SPF is not, because spaces separate SPF terms. If you split a long SPF record, keep the space between terms inside one of the strings.

## cPanel: what the Zone Editor stores

When cPanel installs DKIM through **Email Deliverability**, it writes the record already split. On our lab, the zone file line for `default._domainkey` contained two quoted strings, and DNS returned them like this (strings truncated, lengths added by us):

```
dig +short TXT default._domainkey.example.com @127.0.0.1 | sed -e 's/" "/"\n"/g'
"v=DKIM1; k=rsa; p=MIIBI...
