Skip to content
Keys are generated in your browser · never sent to us

A DKIM key pair, generated on your device, and the record to publish it.

Your browser creates the key with WebCrypto. The public half becomes the TXT record; the private half goes on your mail server. Neither one is sent to DDMARC, and the page keeps no copy once you leave it.

Any name you have not used before on this domain. A date, such as 2026q4, makes the next rotation obvious.

Key size

The key is generated by your browser’s WebCrypto, on this device. Neither half is sent to DDMARC or anywhere else.

Enter your domain and a selector, then generate. The DNS record, the record split for long values, and the private key appear here.
01 — Install the private key

Publish the record, then sign with the key.

The record does nothing until your mail server signs with the matching private key, and signing does nothing until the record resolves. Publish first, confirm it with the DKIM checker, then turn signing on.

01

OpenDKIM

Save the key as /etc/opendkim/keys/yourdomain/selector.private, owned by the opendkim user with mode 600, and add a line for it to KeyTable and SigningTable.

02

rspamd

Save the key where dkim_signing.conf points, by default /var/lib/rspamd/dkim/yourdomain.selector.key, readable only by the _rspamd user.

03

A hosted provider

Google Workspace and Microsoft 365 generate the key for you and show the record to publish, so use theirs. Some platforms, such as Amazon SES, also accept a key you bring.

02 — Or generate it on your server

The same key pair, made with openssl.

If policy says private keys are created on the machine that uses them, run these there. The first writes the private key; the second prints the base64 value that goes after p= in the record.

1 · Private key
openssl genpkey -algorithm RSA -pkeyopt rsa_keygen_bits:2048 -out s1.private.pem
2 · Public key for p=
openssl pkey -in s1.private.pem -pubout -outform DER | openssl base64 -A

Publish it as v=DKIM1; k=rsa; p= followed by the output, at s1._domainkey.yourdomain.com.

03 — FAQ

Frequently asked questions.

No. The key pair is generated by your browser's WebCrypto API on your own device, and neither half is sent to DDMARC or any other server. The page keeps no copy, so reloading it discards the key. Save the private key before you leave.

For the full walkthrough, see the DKIM setup guide.

A signature only counts when it aligns.

DMARC passes on DKIM only when the signing domain matches the From: address. Aggregate reports show which of your senders sign with your key and which sign with their own. Monitor reads them for 2 domains at no charge.

Free plan: 2 domains, no card, no expiry · Trial: card required, billed on day 15 unless you cancel · 14-day money-back on new paid plans