Generate a DKIM key pair, safely, in your browser
Creates a real cryptographic key pair using your browser's own security features — the private key is generated locally and never sent anywhere. For domains running their own mail server.
Generated entirely in your browser using the Web Crypto API — the private key is never sent to our servers, never logged, and isn't stored anywhere. Reload this page and it's gone for good, so copy or download it before you leave.
Your browser doesn't support the Web Crypto API needed to generate keys securely. Try a recent version of Chrome, Firefox, Edge, or Safari.
A short name for this key, chosen by you — it becomes part of the DNS record's location, not a secret. Using a date (like 202601) makes it easy to tell keys apart if you ever rotate to a new one.
This record will be published at:
RSA 2048-bit is the safe default: every major mail provider supports verifying it. Ed25519 produces a much shorter DNS record and is cryptographically strong, but some receiving mail servers still don't support it — only choose it once you've confirmed your recipients do.
This is the only time you'll see this private key — we don't store it, and there's no way to retrieve it again later. Copy or download it now, before you navigate away or reload this page.
This goes into your mail server's DKIM signing configuration (for example OpenDKIM's KeyFile, or your MTA's equivalent) — never into DNS, and never shared with anyone.
Need the split version for a strict DNS provider?
Some DNS providers reject a single TXT value longer than 255 characters and require it split into quoted chunks like this. Most modern providers handle the long version above automatically — only use this if yours shows an error.
Free tool, provided without warranty or professional liability on our part — by using it, you agree we accept no liability for the result. Need a guarantee? Hire a qualified professional instead. Details in the Free Tools section of our Terms of Service.
How to add this to your domain
-
1
Copy the DNS record above.
-
2
Log in to your domain's DNS provider (your registrar or DNS host).
-
3
Create a new TXT record using the host/name shown in the preview above — for example default._domainkey.yourdomain.com, not the bare domain.
-
4
Paste the record as the value, and save.
-
5
Install the private key in your mail server's DKIM signing configuration (see your MTA or DKIM software's documentation), then give the DNS change time to propagate before verifying.
If you send mail through Google Workspace, Microsoft 365, SendGrid, Mailgun, or a similar provider, don't use this tool — they generate and manage their own DKIM key internally. Just enable DKIM in their admin panel and publish the record they give you instead.
Verify your SPF, DKIM, and DMARC setup with our free checker →
DKIM proves your mail wasn't altered — not that the sender is trustworthy
Even a perfectly signed, verified email can come from a genuine account that's been compromised. Adlerwacht adds a passkey check on top, so the attachment itself stays protected either way.
Try Adlerwacht free for 30 days