Skip to content
DKIM

Weak DKIM key: upgrade to 2048 bits

Why DKIM keys under 1024 bits fail, why 1024-bit keys should be replaced, and how to rotate to 2048-bit keys in Microsoft 365 and Google Workspace.

By the Domain Health Hub team · Updated

In short
  • RFC 8301 says signers must use RSA keys of at least 1024 bits and should use 2048.
  • Keys under 1024 bits aren't trusted, so we fail them. 1024-bit keys still work, so we warn.
  • Rotate to 2048 bits: publish the new key, switch signing over, then remove the old one.

What the error means

A DKIM key's strength is its length in bits. RFC 8301, which updated DKIM in 2018, says signers must use RSA keys of at least 1024 bits and should use 2048, and that receivers must not treat keys under 1024 bits as valid. So we raise two different issues:

Under 1024
A fail. Receivers ignore the signature, so DKIM is effectively off.
1024 bits
A warning. It still verifies, but 2048 is the recommended size.
2048 bits
Passes. Ed25519 keys pass too.

Why it matters

Short RSA keys can be factored with enough computing power, and someone holding your private key can sign email that passes DKIM and DMARC as your domain. 512-bit keys have been broken in public for years. 1024-bit keys aren't known to be broken, but they're the minimum, and older domains often still have the 1024-bit key their provider created years ago.

How to confirm it

Look up the TXT record at <selector>._domainkey.<domain>. The longer the p= value, the bigger the key: about 216 characters for 1024 bits, about 392 for 2048. Our checker reports the exact size per selector.

How to fix it

Rotating a key never needs downtime if you do it in order: publish the new key, switch signing to it, wait a few days for email in transit, then remove the old key.

Microsoft 365

In the Defender portal's DKIM settings, choose the domain and rotate the keys. Microsoft uses two selectors so it can rotate between them, and the CNAMEs you published for selector1 and selector2 don't change.

Google Workspace

In Apps, Google Workspace, Gmail, Authenticate email, generate a new record with a 2048-bit key. To rotate without a gap, use a new selector name (such as google2), publish it, start authentication, and delete the old record a few days later.

Other services and your own server

Generate a new 2048-bit key in the service's DKIM settings, or with your mail server's tools, under a new selector name. Services that use CNAMEs (SendGrid, Mailchimp) manage their own keys.

Questions

Will a 2048-bit key fit in my DNS?

A TXT record holds strings of up to 255 characters, and a 2048-bit key is longer than that. It must be split into several strings in one record. Most DNS providers do this for you; a few need you to paste it in quoted parts.

What about Ed25519 keys?

RFC 8463 adds Ed25519 keys, which are short and strong. Not every receiver checks them yet, so they're used alongside an RSA key, not instead of one.

Hear about it the day it breaks.

Daily checks on every client domain, alerts when something changes, and a monthly report card your clients will understand.

Start 28-day free trial