Skip to main content
Version: 1.28 (Current)

Security

Audience: Low-code Engineers

Skill Prerequisites: Actions, Tokens

The Security add-on adds two actions for DKIM email keys. Generate RSA Keys creates an RSA key pair in base64 and PEM formats. Verify DKIM DNS Record checks whether a domain's DKIM record holds the public key you expect. Together they let you build a setup flow where a customer publishes a DKIM key for their domain.

note

These actions are part of the Security add-on (DnnSharp.Security, product code SECURITY). The add-on is installed separately. The actions don't check the license when they run. If you don't see these two actions in the Security group, the add-on isn't installed.

The other actions in the Security group, for AES and RSA encryption, connector values and roles, are part of the platform. See Security.

Choosing an action​

ActionWhat it doesUse it to
Generate RSA KeysCreates a new RSA key pair, as base64 and PEM.Create a DKIM key pair, or a key pair for a partner system that expects PEM keys.
Verify DKIM DNS RecordChecks whether a domain's DKIM TXT record holds the public key you expect, and saves True or False.Confirm that a customer has published the DKIM record you gave them.

Setting up DKIM for a customer domain​

DKIM lets a mail server sign outgoing email with a private key. Receiving servers check the signature against a public key that the domain owner publishes in DNS, in a TXT record at <selector>._domainkey.<domain>. These actions only create keys and read DNS. Plant an App doesn't sign email with DKIM itself. The SMTP server or email provider that sends your mail does.

  1. Create the keys. Run Generate RSA Keys with a Key Length of 2048, and an Output Token such as Dkim.
  2. Save the private key. Store [Dkim:PrivateKeyPem] somewhere protected, for example with Add Connector, and give it to the mail server that signs the email.
  3. Show the DNS record. Ask the customer to add a TXT record named <selector>._domainkey.<domain> with the value v=DKIM1; k=rsa; p=[Dkim:PublicKey].
  4. Check the record. Run Verify DKIM DNS Record with the domain, the selector and [Dkim:PublicKey]. A False result can mean that DNS isn't updated yet, so let the customer try again later.

Keys and checks​

  • Change the default key length. Generate RSA Keys defaults to 1024 bits, which is too weak for new keys. Use 2048, or 4096 for long-lived keys that your DNS provider can hold.
  • Protect the private key. It isn't password protected. Don't log it, email it or send it to the browser.
  • Each run creates a new pair. The action doesn't save the keys. If you run it again, anything tied to the old public key stops working.
  • Not for RSA Encrypt or RSA Decrypt. Those actions need keys in .NET XML format, and Generate RSA Keys creates base64 and PEM keys. See Key formats.
  • The DKIM check is basic. The comparison is exact and case-sensitive, a TXT record without a p= tag passes, and only RSA keys match. Don't rely on it alone to prove the right key is published. See How the record is checked.
  • DNS errors fail the action. A missing record gives False, but an unreachable DNS server raises an error. Catch it with Execute Actions if you need to.

For encryption and roles, see the Security actions. For sending email, see Email. For all add-ons, see Add-ons.

Revised 10/02/2026