When a change is necessary

  • The key is too short. 1024 bits is obsolete; 2048 bits is the standard. Anything below should be replaced, not eventually.
  • The private key may have leaked — after a server move, a backup held elsewhere, or an incident. Then the change is urgent.
  • On a schedule. Every six to twelve months is customary. The benefit is limited while the key is stored safely — but a rollover you have rehearsed goes faster when it counts.

A change is not called for because a single message showed dkim=fail. That is almost always something altering the message in transit, not the key.

Why the selector solves this

The selector in the header tells the receiver which DNS entry to read:

DKIM-Signature: v=1; a=rsa-sha256; d=yourdomain.com; s=k2601; ... ↑ selector → k2601._domainkey.yourdomain.com

Two selectors can live in DNS at the same time. Messages signed before the switch keep pointing at the old entry; new ones at the new entry. As long as both resolve, either passes.

The order

  1. Generate a new key pair under a new selector name. A date as the name makes it obvious later how old a key is.
  2. Publish the public part in DNS — and wait for propagation. Only once the new entry resolves at several resolvers do you continue. With a high TTL that can take hours.
  3. Switch signing. Only now point the mail server or provider at the new selector. This order is the whole point: signing first and publishing afterwards produces messages in between whose key exists nowhere.
  4. Leave the old entry in place — at least seven days, better fourteen. Messages signed with the old selector can still be in flight that long, through delayed forwards or mailing lists.
  5. Remove the old entry. On suspicion of compromise, immediately rather than after seven days — the short failure window is then the lesser evil.

Generating the key

openssl genrsa -out k2601.private 2048 openssl rsa -in k2601.private -pubout -outform PEM -out k2601.public

The DNS entry carries the public part without the BEGIN and END lines and without line breaks:

k2601._domainkey.yourdomain.com. IN TXT "v=DKIM1; k=rsa; p=MIIBIjANBgkqhk..."

A 2048-bit key exceeds the 255-character limit of a single TXT string. The value therefore has to be split into several strings — most DNS interfaces do that themselves. The parts must not be joined with spaces, or the key material is destroyed.

Verification

After the switch the DMARC reports show within two days whether DKIM still passes in alignment. For faster certainty, send a message to hello@analyzemy.email — the report names the selector, key strength, algorithm and the signed headers.

Verify your work

Once the DNS change is live, send an email to hello@analyzemy.email and check in the report whether it took effect.

Analyze your email now

Last updated: · All guides