Short answer: Enter your domain, pick a selector and key size, and the generator creates an RSA key pair in your browser. You get the TXT record to publish at selector._domainkey.yourdomain, the private key in PKCS#1 and PKCS#8 PEM format, and install steps for Postfix with OpenDKIM, Exim, cPanel or DirectAdmin. The private key is generated locally and never sent to srvScripts.
Built and tested in Chromium on 6 Oct 2026; runs entirely in your browser.
Private key safety. The key pair is generated in your browser with the Web Crypto API and is never sent to srvScripts. This page loads no analytics, ads or other third-party scripts, and your browser is told to block connections to other sites while it is open. Copy the private key straight to your mail server and do not keep it in email or chat. If your policy does not allow keys to be generated in a web page, create them on the server instead:
openssl genrsa -out dkim.private 2048
# the p= value for the DNS record:
openssl rsa -in dkim.private -pubout -outform DER | openssl base64 -ATable of Contents
How to use the DKIM key generator
- Enter the domain that appears in your From address, for example
example.com. - Choose a selector. Leave it blank to get the platform default:
defaultfor cPanel,xfor DirectAdmin, or a dated selector such ass202610elsewhere. - Keep 2048-bit unless your DNS host cannot store a TXT record of about 410 characters.
- Pick where the key will be installed, then press Generate key pair.
- Copy the private key to your mail server straight away. It is not stored anywhere, so reloading the page loses it.
- Publish the TXT record, wait for DNS to update, then test with the DKIM checker.
The key is made with the browser’s Web Crypto API (RSASSA-PKCS1-v1_5, public exponent 65537). This page loads no analytics or advertising scripts, and the browser is told to block connections to other sites while it is open.
What the output means
| Field | What it is |
|---|---|
| DNS record name | selector._domainkey.domain. Receivers look the key up here using the s= and d= values in the DKIM-Signature header. |
| Record value | v=DKIM1; k=rsa; p=…. The p= value is the base64 public key, in the same SubjectPublicKeyInfo form that openssl rsa -pubout produces. |
| Value as quoted strings | Shown when the value is longer than 255 characters. A single DNS string holds at most 255 bytes, so a 2048-bit record is stored as two strings. |
| Private key (PKCS#1) | Starts BEGIN RSA PRIVATE KEY. Accepted by OpenDKIM, Exim and cPanel’s API. |
| Private key (PKCS#8) | The same key in the newer BEGIN PRIVATE KEY wrapper. Use it only if your software asks for it. |
| Public key (PEM) | Needed for DirectAdmin, which keeps dkim.public.key next to the private key. |
| Install table | File paths, configuration lines and a check command for the platform you picked. |
Examples
Postfix with OpenDKIM
For selector s202610 on example.com the tool tells you to save the key as /etc/opendkim/keys/example.com/s202610.private, owned by opendkim with mode 600, and to add these lines:
# /etc/opendkim/KeyTable
s202610._domainkey.example.com example.com:s202610:/etc/opendkim/keys/example.com/s202610.private
# /etc/opendkim/SigningTable (opendkim.conf: SigningTable refile:/etc/opendkim/SigningTable)
*@example.com s202610._domainkey.example.com
After the DNS record is live, opendkim-testkey -d example.com -s s202610 -vvv checks that the published key matches.
cPanel and DirectAdmin
cPanel’s Exim configuration signs with the selector default and reads keys from /var/cpanel/domain_keys/private/; DirectAdmin signs with the selector x and reads /etc/virtual/example.com/dkim.private.key. We confirmed both on our cPanel 11.138 and DirectAdmin 1.712 lab servers. On these panels the simplest route is to let the panel create the key; use this tool when you need to install a key you control, for example to keep the same key across a migration. cPanel accepts your own key through WHM API 1 install_dkim_private_keys (parameters domain and key).
Check the key on the server
openssl rsa -in /etc/opendkim/keys/example.com/s202610.private -pubout -outform DER | openssl base64 -A
The output must be exactly the text after p= in your DNS record.
Common mistakes
- Wrong selector for the panel. cPanel only uses
defaultand DirectAdmin only usesx. The tool warns you if the selector does not match. - Key readable by other users. OpenDKIM refuses key files that other users can read (its RequireSafeKeys option is on by default). Use
chmod 600. - Breaking the record when pasting. Some DNS panels add a space where the value is split. Paste the record into the DNS TXT splitter in join mode to check it.
- Using 1024-bit keys by habit. RFC 8301 says signers must use at least 1024 bits and should use 2048 bits.
- Two keys, one selector. When you rotate keys, publish the new key under a new selector, switch signing to it, and remove the old record a few days later.
Official documentation: RFC 6376: DKIM · RFC 8301: DKIM key sizes · cPanel WHM API: install_dkim_private_keys
Related: DKIM Checker · SPF, DKIM and DMARC in cPanel DNS: Setup and Checks · DirectAdmin Rspamd vs SpamAssassin: DKIM and DMARC Setup · Postfix MailBaby Smarthost on Ubuntu and Debian: Secure Setup · DMARC Record Generator
See also: Find a DKIM Selector: Headers, Panel Defaults and Key Checks · Split a 2048-bit DKIM TXT Record Over 255 Characters · DNS TXT Record Splitter: Split Long Values Into 255-Byte Strings
Frequently asked questions
Is it safe to generate a DKIM private key in a browser?
The key is created by your browser’s Web Crypto API and is never sent to srvScripts. If your security policy forbids generating keys in a web page, run openssl genrsa on the server instead; the command is shown on this page.
Should I use a 1024-bit or 2048-bit DKIM key?
Use 2048 bits. RFC 8301 requires at least 1024 bits and recommends 2048. Only fall back to 1024 if your DNS host cannot store a TXT record longer than 255 characters.
Which private key format do I need?
Most mail software reads either. Use the PKCS#1 key (BEGIN RSA PRIVATE KEY) unless your software asks for PKCS#8 (BEGIN PRIVATE KEY).
Why is my DKIM record split into two strings?
A single DNS character-string holds at most 255 bytes. A 2048-bit DKIM record is about 410 characters, so it is stored as two strings that receivers join back together.
What selector should I choose?
Any short name made of letters, digits and hyphens. A date-based selector such as s202610 makes rotation easy. On cPanel use default and on DirectAdmin use x.