Free Tool

Generate a DKIM key pair, safely, in your browser

Creates a real cryptographic key pair using your browser's own security features — the private key is generated locally and never sent anywhere. For domains running their own mail server.

Generated entirely in your browser using the Web Crypto API — the private key is never sent to our servers, never logged, and isn't stored anywhere. Reload this page and it's gone for good, so copy or download it before you leave.

A short name for this key, chosen by you — it becomes part of the DNS record's location, not a secret. Using a date (like 202601) makes it easy to tell keys apart if you ever rotate to a new one.

This record will be published at:

RSA 2048-bit is the safe default: every major mail provider supports verifying it. Ed25519 produces a much shorter DNS record and is cryptographically strong, but some receiving mail servers still don't support it — only choose it once you've confirmed your recipients do.

Free tool, provided without warranty or professional liability on our part — by using it, you agree we accept no liability for the result. Need a guarantee? Hire a qualified professional instead. Details in the Free Tools section of our Terms of Service.

How to add this to your domain

  1. 1

    Copy the DNS record above.

  2. 2

    Log in to your domain's DNS provider (your registrar or DNS host).

  3. 3

    Create a new TXT record using the host/name shown in the preview above — for example default._domainkey.yourdomain.com, not the bare domain.

  4. 4

    Paste the record as the value, and save.

  5. 5

    Install the private key in your mail server's DKIM signing configuration (see your MTA or DKIM software's documentation), then give the DNS change time to propagate before verifying.

If you send mail through Google Workspace, Microsoft 365, SendGrid, Mailgun, or a similar provider, don't use this tool — they generate and manage their own DKIM key internally. Just enable DKIM in their admin panel and publish the record they give you instead.

Verify your SPF, DKIM, and DMARC setup with our free checker →

DKIM proves your mail wasn't altered — not that the sender is trustworthy

Even a perfectly signed, verified email can come from a genuine account that's been compromised. Adlerwacht adds a passkey check on top, so the attachment itself stays protected either way.

Try Adlerwacht free for 30 days