Security
Audience:
Low-code EngineersSkill Prerequisites:
Actions,Tokens
The Security add-on adds two actions for DKIM email keys. Generate RSA Keys creates an RSA key pair in base64 and PEM formats. Verify DKIM DNS Record checks whether a domain's DKIM record holds the public key you expect. Together they let you build a setup flow where a customer publishes a DKIM key for their domain.
These actions are part of the Security add-on (DnnSharp.Security, product code SECURITY). The add-on is installed separately. The actions don't check the license when they run. If you don't see these two actions in the Security group, the add-on isn't installed.
The other actions in the Security group, for AES and RSA encryption, connector values and roles, are part of the platform. See Security.
Choosing an action
| Action | What it does | Use it to |
|---|---|---|
| Generate RSA Keys | Creates a new RSA key pair, as base64 and PEM. | Create a DKIM key pair, or a key pair for a partner system that expects PEM keys. |
| Verify DKIM DNS Record | Checks whether a domain's DKIM TXT record holds the public key you expect, and saves True or False. | Confirm that a customer has published the DKIM record you gave them. |
Setting up DKIM for a customer domain
DKIM lets a mail server sign outgoing email with a private key. Receiving servers check the signature against a public key that the domain owner publishes in DNS, in a TXT record at <selector>._domainkey.<domain>. These actions only create keys and read DNS. Plant an App doesn't sign email with DKIM itself. The SMTP server or email provider that sends your mail does.
- Create the keys. Run Generate RSA Keys with a Key Length of
2048, and an Output Token such asDkim. - Save the private key. Store
[Dkim:PrivateKeyPem]somewhere protected, for example with Add Connector, and give it to the mail server that signs the email. - Show the DNS record. Ask the customer to add a TXT record named
<selector>._domainkey.<domain>with the valuev=DKIM1; k=rsa; p=[Dkim:PublicKey]. - Check the record. Run Verify DKIM DNS Record with the domain, the selector and
[Dkim:PublicKey]. AFalseresult can mean that DNS isn't updated yet, so let the customer try again later.
Keys and checks
- Change the default key length. Generate RSA Keys defaults to 1024 bits, which is too weak for new keys. Use 2048, or 4096 for long-lived keys that your DNS provider can hold.
- Protect the private key. It isn't password protected. Don't log it, email it or send it to the browser.
- Each run creates a new pair. The action doesn't save the keys. If you run it again, anything tied to the old public key stops working.
- Not for RSA Encrypt or RSA Decrypt. Those actions need keys in .NET XML format, and Generate RSA Keys creates base64 and PEM keys. See Key formats.
- The DKIM check is basic. The comparison is exact and case-sensitive, a TXT record without a
p=tag passes, and only RSA keys match. Don't rely on it alone to prove the right key is published. See How the record is checked. - DNS errors fail the action. A missing record gives
False, but an unreachable DNS server raises an error. Catch it with Execute Actions if you need to.
For encryption and roles, see the Security actions. For sending email, see Email. For all add-ons, see Add-ons.
Revised 10/02/2026