DKIM-Schlüsselgenerator
Generate a DKIM key pair, get the DNS record and private key it produces, or paste a record you already have and check it. The key pair is generated locally in your browser and never sent anywhere.
Was ist DKIM?
DKIM (DomainKeys Identified Mail) attaches a digital signature to every message you send, using a private key only your mail server knows. The receiving mailbox looks up the matching public key in your DNS and checks the signature, proof the message really came from you and wasn't altered in transit.
The key pair is generated once. The private key stays on your mail server or your email service provider, where it signs outgoing mail. The public key goes into a DNS TXT record at a location called the selector. That's the only part this tool publishes for you.
Selektor
A short name that lets you run more than one key at once, useful for rotating keys or running several sending services side by side.
Öffentlicher Schlüssel (DNS)
Published as a TXT record at selector._domainkey.yourdomain.com. Anyone can look it up: that's the point.
Privater Schlüssel (Ihr Server)
Wird geheim gehalten und dort installiert, wo Ihre Mails tatsächlich signiert werden. Veröffentlichen Sie ihn niemals und senden Sie ihn nirgendwo anders hin.
DKIM on its own only proves a message wasn't tampered with. It's DMARC that decides what happens when a message fails. Once DKIM is signing cleanly, the DMARC policy generator is the natural next step.
Schlüssel generieren
Fill in your domain and selector, pick a key size, and generate. The DNS record on the right updates with it. Already have a record? Paste it in to check it.
Schlüsselpaar generieren
Runs entirely in your browser. The private key is never sent anywhere.
Schlüsselgröße
2048-Bit ist die aktuelle Empfehlung. 1024-Bit ist schwächer, aber kürzer — das ist relevant, wenn Ihr DNS-Anbieter Probleme mit langen TXT-Einträgen hat.
Hashes auf SHA-256 beschränken
hOnly allow SHA-256 signatures. Leaving this off also accepts the older, weaker SHA-1. Most senders should keep this on.
Auf E-Mail beschränken
sBeschränkt diesen Schlüssel auf das Signieren von E-Mails, damit er nicht zum Signieren anderer Inhalte wiederverwendet werden kann, die den s-Tag prüfen.
Testmodus
t=yAsk receivers not to act on a signature failure yet. Useful while you roll this out. Turn it off once mail is signing and passing cleanly.
Strikte Subdomain-Übereinstimmung
t=sErfordert, dass die Signatur-Domain exakt mit Ihrer Absender-Domain übereinstimmt, sodass dieser Schlüssel nicht zum Signieren für eine Subdomain verwendet werden kann.
Privater Schlüssel
Generieren Sie ein Schlüsselpaar, um Ihren privaten Schlüssel hier zu sehen.
DNS-Eintrag
Veröffentlichen Sie diesen TXT-Eintrag bei Ihrer Domain.
Add this as a new record at your DNS provider. “Type” and “Host” are the fields it asks for. Some providers want just mail._domainkey in the host field and add the domain for you.
Paste an existing record here to check it. It won't recover a private key.