DKIM key is critically weak (under 1024 bits)
Check id: dkim.key_weak · fix effort: medium
What it means
Your mail signing key is short enough to be cracked with modest resources. Someone could forge validly signed mail as you.
The technical detail
RSA under 1024 bits is factorable at low cost. RFC 8301 requires 1024 minimum and recommends 2048.
How to fix it
- Generate a new 2048-bit key at your provider and publish it under a new selector.
- Switch signing to the new selector, then revoke the old key (empty
p=).
Does your domain have this problem?
Run a free scan, takes about ten seconds.