What does this tool do, and what does it not do?
It creates an RSA key pair with your browser's own Web Crypto, then formats the public half into the DNS TXT record you publish and the private half into a PEM file for your mail server. It does not switch DKIM on: signing happens in your mail server and verification happens at the receiver. Until your server is configured to sign with this key, publishing the record changes nothing.