DKIM key at {selector} is only 1024 bits
ATTENTIONWhat it means
The key at selector1 is the bare minimum receivers will accept. It works today, and the standard asks for 2048, the gap between "accepted" and "trusted" is where deliverability quietly lives.
How to fix it
Rotate to a 2048-bit key when convenient. Most providers do it in one click and keep the old selector alive during the change.
Check your own domain
This page describes the condition. To find out whether your domain has it, run the DKIM test or the full checkup, which examines every record at once.
Understand it properly
This page covers one condition. For the whole picture, What is DKIM, selectors and key strength, or start at the Health Library.
Where this comes from
We judge this against RFC 8301 section 3.2. Every finding on this site cites the specification behind it so you can check the work rather than take our word for it.
Other DKIM conditions
DKIM_KEY_WEAK_1024
Every fix on this site is yours to implement. If you would rather someone did it, I take this work directly.