A DKIM key pair, generated on your device, and the record to publish it.
Your browser creates the key with WebCrypto. The public half becomes the TXT record; the private half goes on your mail server. Neither one is sent to DDMARC, and the page keeps no copy once you leave it.
Any name you have not used before on this domain. A date, such as 2026q4, makes the next rotation obvious.
The key is generated by your browser’s WebCrypto, on this device. Neither half is sent to DDMARC or anywhere else.
Publish the record, then sign with the key.
The record does nothing until your mail server signs with the matching private key, and signing does nothing until the record resolves. Publish first, confirm it with the DKIM checker, then turn signing on.
OpenDKIM
Save the key as /etc/opendkim/keys/yourdomain/selector.private, owned by the opendkim user with mode 600, and add a line for it to KeyTable and SigningTable.
rspamd
Save the key where dkim_signing.conf points, by default /var/lib/rspamd/dkim/yourdomain.selector.key, readable only by the _rspamd user.
A hosted provider
Google Workspace and Microsoft 365 generate the key for you and show the record to publish, so use theirs. Some platforms, such as Amazon SES, also accept a key you bring.
The same key pair, made with openssl.
If policy says private keys are created on the machine that uses them, run these there. The first writes the private key; the second prints the base64 value that goes after p= in the record.
openssl genpkey -algorithm RSA -pkeyopt rsa_keygen_bits:2048 -out s1.private.pem
openssl pkey -in s1.private.pem -pubout -outform DER | openssl base64 -A
Publish it as v=DKIM1; k=rsa; p= followed by the output, at s1._domainkey.yourdomain.com.
Frequently asked questions.
No. The key pair is generated by your browser's WebCrypto API on your own device, and neither half is sent to DDMARC or any other server. The page keeps no copy, so reloading it discards the key. Save the private key before you leave.
For the full walkthrough, see the DKIM setup guide.
DMARC Report Analyzer
Paste or upload a DMARC aggregate (RUA) report and see total volume, pass/fail rates, and which senders are failing. Runs in your browser.
DMARC Record Generator
Create a valid DMARC record for your domain. Configure policy, reporting emails, and advanced options.
SPF Record Generator
Build an SPF record to authorize your email senders. Includes common services and DNS lookup counter.
MTA-STS Record and Policy Generator
Build the _mta-sts TXT record and the mta-sts.txt policy file together, with MX patterns and max_age checked.
TLS-RPT Record Generator
Build the _smtp._tls record that asks senders to report failed TLS connections, with email and https destinations checked.
SPF Checker
Look up a domain's SPF record, walk every include, and count DNS lookups against the limit of 10.
Domain Checker
Check your domain's email authentication setup. See your SPF, DKIM, DMARC, and MTA-STS configuration.
DMARC Checker
Look up any domain's DMARC record and get every tag explained — policy, alignment, reporting, and coverage.
DKIM Checker
Check a domain's DKIM record by selector. See the key type, size, and each tag, with quick-picks for common providers.
MTA-STS & TLS-RPT Checker
Check a domain's MTA-STS policy record and TLS-RPT reporting — the pair that forces inbound mail over TLS.
BIMI Checker
Look up a domain's BIMI record, preview the logo, and confirm the VMC and DMARC enforcement it requires.
A signature only counts when it aligns.
DMARC passes on DKIM only when the signing domain matches the From: address. Aggregate reports show which of your senders sign with your key and which sign with their own. Monitor reads them for 2 domains at no charge.