You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PHP生成DKIM密钥适配DNS提供商1024位RSA需求的问询

调整PHP代码生成1024位RSA的DKIM密钥

当前使用的PHP代码生成的是2048位RSA密钥搭配SHA256摘要的DKIM密钥,但DNS提供商仅支持1024位RSA密钥,以下是调整后的完整代码及关键说明:

<?php

//Set these to match your domain and chosen DKIM selector
$domain = 'example.com';
$selector = 'phpmailer';

//Private key filename for this selector
$privatekeyfile = $selector . '_dkim_private.pem';
//Public key filename for this selector
$publickeyfile = $selector . '_dkim_public.pem';

if (file_exists($privatekeyfile)) {
    echo "Using existing keys - if you want to generate new keys, delete old key files first.\n\n";
    $privatekey = file_get_contents($privatekeyfile);
    $publickey = file_get_contents($publickeyfile);
} else {
    //Create a 1024-bit RSA key with an SHA256 digest
    $pk = openssl_pkey_new(
        [
            'digest_alg' => 'sha256',
            'private_key_bits' => 1024, // 关键修改:将密钥长度改为1024位
            'private_key_type' => OPENSSL_KEYTYPE_RSA,
        ]
    );
    //Save private key
    openssl_pkey_export_to_file($pk, $privatekeyfile);
    //Save public key
    $pubKey = openssl_pkey_get_details($pk);
    $publickey = $pubKey['key'];
    file_put_contents($publickeyfile, $publickey);
    
    $privatekey = file_get_contents($privatekeyfile);
}
echo "<pre>"."Private key (keep this private!):\n\n" . $privatekey;
echo "\n\nPublic key:\n\n" . $publickey;

//Prepare public key for DNS, e.g.
//phpmailer._domainkey.example.com IN TXT "v=DKIM1; h=sha256; t=s; p=" "MIIBIjANBg...oXlwIDAQAB"...
$dnskey = "$selector._domainkey.$domain IN TXT";
$dnsvalue = '&quot;v=DKIM1; h=sha256; t=s; p=&quot; ';
//Some DNS servers don't like ;(semi colon) chars unless backslash-escaped
$dnsvalue2 = '&quot;v=DKIM1\; h=sha256\; t=s\; p=&quot; ';

//Strip and split the key into smaller parts and format for DNS
//Many DNS systems don't like long TXT entries
//but are OK if it's split into 255-char chunks
//Remove PEM wrapper
$publickey = preg_replace('/^-+.*?-+$/m', '', $publickey);
//Strip line breaks
$publickey = str_replace(["\r", "\n"], '', $publickey);
//Split into chunks
$keyparts = str_split($publickey, 253); //Becomes 255 when quotes are included
//Quote each chunk
foreach ($keyparts as $keypart) {
    $dnsvalue .= '&quot;' . trim($keypart) . '&quot; ';
    $dnsvalue2 .= '&quot;' . trim($keypart) . '&quot; ';
}
echo "\n\nDNS key:\n\n" . trim($dnskey);
echo "\n\nDNS value:\n\n" . trim($dnsvalue);
echo "\n\nDNS value (with escaping):\n\n" . trim($dnsvalue2);
?>

关键修改说明

  • 核心调整:在openssl_pkey_new的配置数组中,将private_key_bits的值从2048改为1024,直接生成符合DNS提供商要求的1024位RSA密钥。
  • 前置操作:运行修改后的代码前,必须删除之前生成的phpmailer_dkim_private.pem和phpmailer_dkim_public.pem文件,否则代码会优先使用已存在的2048位密钥。
  • SHA256摘要保留:digest_alg设置为sha256是邮件签名的哈希算法,与密钥长度无关,无需修改,DKIM协议支持1024位RSA搭配SHA256签名。

内容的提问来源于stack exchange,提问作者Abhinav

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.09 04:15:42