DKIM DNS records points to expired and 1024 bit keys when we selected 2048 bit key

0

We are using Amazon SES to send e-mails. We have enabled DKIM for a domain with 2048 bits key (previously we had it enabled with 1024 bits key). The service indicates to create 3 DNS records: one of them points to a 2048 bits key, another to a 1024 bits key and the last one to a expired key. The internal policies report a security issue because the DNS records do not point to 2048 bits keys. If we remove the non-2048 bits key records, then SES stops sending e-mails and complains. Any suggestions on just having DNS records with 2048 bits keys please? Is it compulsory to have the 1024 bits and the expired one please?

2개 답변
1
수락된 답변

Hi Miquel,

I've had the same questions as you and you need indeed to keep all three records. This is how EasyDKIM works. 2 selectors are used for keys rotation (old one and new one). You cannot force the rotation. This is handled by AWS and occurs once a year, though A makes no commitment on this (not documented). The third key is used as backup when upgrading key length. It will be used in case of rollback. It will stay forever. You cannot delete it.

AWS always uses one selector at a given time. You can verify what selector is used by sending an email from your domain.

AWS documentation could be improved on how EasyDkim works. It would be nice also to see in the admin console which key is active.

Regards, V.P.

vp
답변함 9달 전
profile picture
전문가
검토됨 한 달 전
1

Hi Miquel,

Assuming you have generated this using Easy DKIM in SES. I do not believe any newly generated records for the 2048 bits key should not point to the 1048-bit key or an expired key. It may be an issue where DNS propagation takes some time resulting in some records still pointing to old/expired keys. (According to AWS it may take up to 72 hours for DNS propagation)

Please verify the CNAME records for the newly generated 2048 bits key is accurate in your hosting provider or else regenerate the keys and try adding them to your DNS provider.

profile picture
Bisina
답변함 10달 전
  • Yes, it is using the Easy DKIM in SES. How do I regenerate the keys please? Thanks a lot for your answer

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠