DKIM key too short
DKIM key length is below accepted operational guidance.
Problem summary
DKIM key length is below accepted operational guidance.
Symptoms
- Operational guidance or auditors flag short DKIM keys
- Providers recommend 2048-bit keys while 1024-bit remains
- Some receivers warn on weak keys
Possible causes
- Legacy 1024-bit key still active
- ESP default not raised
- Rotation never completed
How to diagnose
- Inspect key length in the ESP and DNS key record
- Confirm receiver/policy requirements for your industry
How to fix
- Generate a 2048-bit (or current recommended) key on a new selector
- Publish the new selector, dual-sign if supported, then retire the old selector
- Update all streams using the short key
How to verify
- New selector publishes the stronger key
- Production mail verifies with the new selector
Prevention
- Include key-length checks in annual auth review
- Prefer provider defaults that meet current guidance
When to escalate
- Production mail is failing for a material share of recipients after remediation attempts