Amazon Route 53 DKIM Splitter
Split long DKIM keys for AWS Route 53 TXT records
DKIM Key Splitter
Paste your 2048-bit or 4096-bit DKIM key below. This tool will automatically split it into segments compatible with Amazon Route 53's 255-character limit for TXT records.
What is DKIM and Why Does It Matter?
DKIM (DomainKeys Identified Mail) is a critical email authentication method that helps protect your domain from email spoofing, phishing attacks, and spam. When you send an email, DKIM adds a digital signature to the message header, which receiving mail servers can verify using your public DKIM key published in DNS.
Modern email providers like Google Workspace, Microsoft 365, and other enterprise email services use 2048-bit or 4096-bit DKIM keys for enhanced security. These longer keys provide stronger cryptographic protection but create a technical challenge: they exceed Amazon Route 53's 255-character limit for TXT record values.
Without proper DKIM configuration:
- Your legitimate emails may be marked as spam or rejected
- Email deliverability drops significantly
- Your domain reputation suffers
- You fail DMARC authentication checks
- Phishers can more easily impersonate your domain
The Route 53 TXT Record Challenge
Amazon Route 53, like many DNS providers, enforces a 255-character limit per string in TXT records. A 2048-bit DKIM key typically contains 391 characters, and a 4096-bit key can exceed 800 characters. This makes it impossible to paste these keys directly into Route 53. Attempting to do so often results in errors such as TXTRDATATooLong or CharacterStringTooLong.
The solution is to split the DKIM key into multiple quoted strings within a single TXT record. Route 53 will concatenate these strings during DNS resolution, allowing mail servers to retrieve the complete DKIM public key.
Note: This splitting is specific to how you enter the record in Route 53's console. The actual DNS query response will return the complete, concatenated key to mail servers checking your DKIM signature.
How to Use the Route 53 DKIM Splitter
- 1Get your DKIM key from your email provider:
- Google Workspace: Admin Console → Apps → Google Workspace → Gmail → Authenticate email → Generate new record
- Microsoft 365: Microsoft 365 Defender Portal → Email & collaboration → Policies & rules → Threat policies → DKIM
- Other providers: Check your email admin panel or DNS settings documentation
- 2Copy the DKIM public key value - this is typically the part that starts with "p=" or just the long base64-encoded string
- 3Paste it into the tool above and click "Split DKIM Key"
- 4Copy the formatted output and use it in your Route 53 TXT record
- 5Verify your DKIM setup using your email provider's verification tool or a third-party DKIM checker
Common DKIM Setup Scenarios
Google Workspace DKIM for Route 53
Google Workspace provides a DKIM selector (usually "google") and a 2048-bit public key. Create a TXT record with the name:
google._domainkey.yourdomain.comUse this tool to split the p= value Google provides, then paste the formatted output into the record value field.
Microsoft 365 DKIM for Route 53
Microsoft 365 uses two DKIM selectors (selector1 and selector2) for key rotation. You'll need to create two CNAME records:
selector1._domainkey.yourdomain.comselector2._domainkey.yourdomain.comFor Microsoft 365 DKIM, use the exact CNAME target values shown in Microsoft Defender (Publish CNAMEs) or Exchange Online PowerShell (Get-DkimSigningConfig). In most Microsoft 365 setups, you do not split a DKIM TXT key for this step.
Microsoft introduced an updated DKIM CNAME target format for new custom domains in May 2025 (with a dynamic partition value like r-v1 or n-v1 under dkim.mail.microsoft). Older custom domains can still use the legacy onmicrosoft.com target format. The old and new formats cannot coexist for the same selector.
SendGrid, Mailgun, or Other ESPs
Most Email Service Providers (ESPs) give you specific DKIM records to add. If the key value exceeds 255 characters, use this tool to split it before adding to Route 53. Follow the ESP's documentation for the exact record name and selector.
Need Help with Email Security & AWS Configuration?
Network Thinking Solutions specializes in enterprise email security, cloud infrastructure, and AWS managed services for businesses in Phoenix, San Luis Obispo, Westlake Village, and Brea.
Our team can help you implement comprehensive email authentication (DKIM, SPF, DMARC), configure AWS Route 53 for optimal performance, and protect your domain from email-based threats.
- Complete DKIM, SPF, and DMARC setup and monitoring
- AWS Route 53 configuration and optimization
- Email security audits and compliance consulting
- Google Workspace and Microsoft 365 administration
- Cloud infrastructure management and support