Back to all tools
Record builder SPF · DKIM · DMARC · MTA-STS · 100% client-side

DKIM Record Generator

Build a valid SPF, DMARC, DKIM or MTA-STS record from a form, then paste it into your DNS. Everything is assembled in your browser, nothing you type here is sent anywhere, including to us.

Your record
.
Type
TXT
Host
.
Value
.
TTL
3600

Host names are shown the way most DNS panels expect them. A few providers want the full name including your domain, if yours shows an existing record as _dmarc.yourdomain.com rather than _dmarc, use the full form.

Questions people ask

What is a DKIM selector?

The label before ._domainkey in the record host. It lets a domain publish several keys at once: your CRM signs with its selector, your mailbox provider with another, and receivers look each one up independently.

My provider gave me a CNAME, not a key. Do I need this?

No. If the platform hands you CNAME targets (HubSpot and Klaviyo do this), publish those CNAMEs exactly as given and the platform hosts the key itself. This generator is for platforms that hand you the raw public key.

Why is my DKIM record split into two strings?

TXT records cap each string at 255 characters and 2048-bit keys are longer than that. DNS panels usually split and rejoin automatically; verifiers concatenate the chunks before parsing. Both halves must be present.