Skip to content
Vectel

Our DKIM key is still 1024-bit, do we need to move to 2048?

1024-bit RSA for DKIM is no longer recommended. Google and Yahoo still accept it, but large receivers lower reputation and security audits flag it. 2048-bit is the practical standard and still fits a DNS TXT record if you split it correctly.

support/email-aflevering/dkim-1024-naar-2048-upgradesteps: 5

Try this first

  1. Generate a new 2048-bit DKIM key in your mail platform with a new selector, for example s2026 next to the existing s1.
  2. Publish the new selector as a TXT record. Many DNS providers split across the 255-character per-string limit automatically, but verify with dig txt s2026._domainkey.yourdomain.com that it assembles correctly.
  3. Switch outgoing signing in the mail platform to the new selector. Keep the old selector around for a few days so mail still in flight can be verified by receivers.
  4. Verify pass via tools like mail-tester.com, dkimvalidator.com or mxtoolbox.
  5. Remove the old selector after a week or two. Only then is the old key truly closed off against replay.

When to bring us in

If you run multiple ESPs or a self-hosted MTA next to Microsoft 365, sequencing matters: every sender must sign before you remove the old key from DNS.

See also

Was this helpful?

None of the above fits?

Describe your situation below. We pass your input plus the steps you already saw to our AI and return tailored next-step advice. If it's too risky to DIY, we'll say so.

Who are you?

For the AI question we need your email and company, so we can follow up if the AI gets stuck, and to prevent abuse.

Limited to 2 questions per hour and 5 per day, kept lean so the AI stays useful. For more, contacting us directly works better for you and us.

Or skip the DIY entirely

Our Managed IT clients do not look these things up. One point of contact, a fixed monthly price, resolved within working hours.