Skip to content
warn

DKIM key length too short — rotate to 2048 bits

DKIM keys under 1024 bits have been treatable as insecure for over a decade, and receivers may disregard signatures made with them, which quietly removes DKIM from your DMARC alignment.

Rotate to 2048 bits. Almost every provider supports it, and many now default to it.

How to fix it

  1. 1Generate a new 2048-bit key in your mail provider and publish it under a new selector.
  2. 2Switch signing to the new selector.
  3. 3Leave the old record in place for a few days so in-flight mail still verifies, then remove it.

Check whether your domain has this problem

Free, no signup, about two seconds. You get the exact record to paste.

Related guides