Free tools for preparing, validating, and scaling outbound email safely.
Generate a DKIM key pair in your browser.
Create an RSA key pair with Web Crypto, copy the public DNS TXT, and export the private PEM — locally. This does not configure your ESP or publish DNS.
Empty
Enter your domain and selector, then generate a DKIM key pair for DNS and ESP setup.
Why this matters
Domain setup is part of safer outbound.
What DKIM does
DKIM adds a cryptographic signature to outbound mail. Receivers verify it against the public key you publish in DNS.
Generated locally
Keys are created with Web Crypto in your browser. The private key never leaves this page unless you copy or download it.
Two steps after generation
Publish the TXT on selector._domainkey.yourdomain.com, then upload the private PEM to your ESP. Every DKIM record is longer than one DNS string, so the generator also gives you the quoted form for providers that do not split it for you.
Related: SPF Record Generator · DMARC Record Generator
Straight answers
DKIM Record Generator FAQ
Which key size should I use?+−
2048 bits is the common default. Use 4096 if your ESP and DNS provider support it — its record is roughly twice as long, and some panels truncate very long TXT records.
Does this configure my ESP?+−
No. You must add the private key in your sending provider and publish the public TXT in DNS yourself.
Can I reuse an existing selector?+−
Each selector needs a matching key pair. If you rotate keys, use a new selector or update both DNS and the ESP together.
Next step
Keys ready. Ready to run outreach you approve first.
OmniReach drafts personalized LinkedIn and email sequences. You review the first touch — nothing sends without a deliberate launch.