DKIM key length too short — rotate to 2048 bits
DKIM keys under 1024 bits have been treatable as insecure for over a decade, and receivers may disregard signatures made with them, which quietly removes DKIM from your DMARC alignment.
Rotate to 2048 bits. Almost every provider supports it, and many now default to it.
How to fix it
- 1Generate a new 2048-bit key in your mail provider and publish it under a new selector.
- 2Switch signing to the new selector.
- 3Leave the old record in place for a few days so in-flight mail still verifies, then remove it.
Check whether your domain has this problem
Free, no signup, about two seconds. You get the exact record to paste.
Related guides
- DKIM record with empty p= — a revoked key still in use
- SPF include points at a domain with no SPF record — a silent PermError
- DMARC record syntax errors that make receivers skip your policy
- DMARC external destination not authorized — why you receive no reports
- Two DMARC records at _dmarc — why your policy is being ignored