Fix a long DKIM TXT value in Amazon Route 53

Route 53 can reject a long DKIM TXT value with CharacterStringTooLong. The fix is to split the value into quoted strings within one TXT record value. A line break in the console’s value field can create a different result: two independent values.

The 255-character limit applies to each string

A TXT record value may contain several quoted strings. For an ASCII DKIM value longer than 255 characters, keep each string at or below that limit and place the strings on the same line.

"first part of the same value" "remaining part of the same value"

The separating space belongs to the record’s representation. It does not add a space to the concatenated DKIM value. Preserve the original characters, including the tags and the complete public key.

Prepare one line from the provider’s value

Use the selector name and complete DKIM value supplied by your mail provider. For example, a selector named mail2025 would use a name such as mail2025._domainkey.example.com. The name and key below are illustrative, not a working DKIM configuration.

This Python example demonstrates splitting an ASCII value into 200-character chunks and verifying that joining the chunks reproduces it:

# Synthetic demonstration only: this is not a valid RSA public key.
value = "v=DKIM1; k=rsa; p=" + "A" * 300
parts = [value[i:i + 200] for i in range(0, len(value), 200)]

assert "".join(parts) == value
assert all(len(part.encode("ascii")) <= 255 for part in parts)
print(" ".join('"' + part + '"' for part in parts))

For a real record, replace the synthetic value with the provider’s complete ASCII DKIM TXT value. Copy the generated quoted strings as one line into one Route 53 value. Do not copy the demonstration key into DNS.

One line and two lines have different meanings

Entry Meaning
"part one" "part two" on one line One TXT value made from two strings.
"part one" and "part two" on separate lines Two TXT values; not two pieces of one DKIM key.

For an API request, the quoted chunks must similarly remain together inside one Value element. The mistake is easy to miss because the console may display the entries in a similar-looking box.

Check the published record

After saving, query the provider’s selector name and compare the returned strings with the original value. On Windows, for example:

Resolve-DnsName -Name mail2025._domainkey.example.com -Type TXT -DnsOnly

Replace the example with your actual selector name. A DNS tool can display one TXT value as several strings; join the strings within that value when comparing the public key. Also use the mail provider’s verification result. A syntactically accepted Route 53 entry does not by itself prove that mail is signed with the corresponding key.

Reference

AWS: Route 53 TXT record values explains the per-string limit, the same-line format, and separate values. Follow your provider’s record type: this procedure addresses a supplied TXT record, rather than converting a provider’s CNAME-based DKIM setup into TXT.