DMARC Engine
Home/Blog/DKIM Key Rotation Strategies for Organisations with High Email Volume and Frequent Staff Changes
Blog

DKIM Key Rotation Strategies for Organisations with High Email Volume and Frequent Staff Changes

Large organisations face DKIM key rotation challenges due to high email volume and staff changes, requiring careful security and deliverability considerations. Automated key rotation can mitigate complexity

2 October 2026 · DMARC Engine · 35 min read

DKIM Key Rotation Strategies for Organisations with High Email Volume and Frequent Staff Changes

The DKIM Key Rotation Conundrum for Large Organisations

For organisations with high email volume and frequent staff changes, DKIM key rotation presents a complex challenge that requires careful consideration of security, deliverability, and operational efficiency. A typical large organisation may have multiple domains, subdomains, and mail streams, each requiring its own set of DKIM keys. For instance, a company like example.com may have separate mail streams for marketing, transactional, and internal communications, each with its own DKIM key.

TXT example.com._domainkey.example.com "v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC4RZBv3nr6jyWlM9Zp2i8W0m6X2F2T0z5hP6G5Y8tTzJF4bDZ7JF4bDZ7JF4bDZ7JF4bDZ7JF4bDZ7JF4bDZ7JF4bDZ7JF4bDZ7JF4bDZ7JF4bDZ7JF4bDZ7JF4bDZ7J"

In a hosted or managed setup, such as the one we provide at DMARC Engine, the complexity of managing multiple DKIM keys is mitigated by our automated key rotation and management features. However, for organisations that manage their own DKIM infrastructure, the process of rotating keys can be time-consuming and prone to errors.
The frequency of staff changes in large organisations also adds to the complexity of DKIM key rotation. When an employee leaves the organisation, their access to the DKIM private key must be revoked to prevent potential misuse. This requires a robust access control system and a well-defined process for key revocation and rotation.
A common mistake made by large organisations is to use a single DKIM key across all their domains and mail streams. While this may seem like a convenient solution, it can lead to security risks and deliverability issues. For example, if a single DKIM key is compromised, it can affect the deliverability of emails across all domains and mail streams.
To mitigate this risk, it is recommended that large organisations use a separate DKIM key for each domain and mail stream. This approach provides an additional layer of security and helps to prevent the compromise of a single key from affecting the entire organisation.
In addition to using separate DKIM keys, large organisations should also implement a regular key rotation schedule. The frequency of key rotation depends on various factors, including the organisation's security posture, email volume, and regulatory requirements. As a general guideline, it is recommended that DKIM keys be rotated every 6-12 months.
However, rotating DKIM keys too frequently can lead to deliverability issues, as some email providers may not be able to verify the new key in time. This can result in emails being flagged as spam or rejected by the recipient's email server.
To avoid this issue, it is essential to plan and execute DKIM key rotation carefully. This includes communicating the key rotation schedule to all stakeholders, including email service providers, and ensuring that all systems and applications are updated with the new key.
In our experience at DMARC Engine, we have seen that a well-planned and executed DKIM key rotation strategy is critical to maintaining email deliverability and security. By using separate DKIM keys for each domain and mail stream, implementing a regular key rotation schedule, and planning the rotation carefully, large organisations can ensure that their emails are delivered securely and reliably.
It is also important to monitor the effectiveness of the DKIM key rotation strategy using aggregate reports. These reports provide valuable insights into the organisation's email authentication and deliverability, helping to identify potential issues and areas for improvement.
For example, the following aggregate report snippet shows the authentication results for a domain using a rotated DKIM key:

<record>
 <row>
 <source_ip>192.0.2.1</source_ip>
 <count>100</count>
 <policy_evaluated>
 <disposition>none</disposition>
 <dkim>pass</dkim>
 <spf>pass</spf>
 </policy_evaluated>
 </row>
</record>

By analysing these reports, organisations can optimise their DKIM key rotation strategy and ensure that their emails are delivered securely and reliably.
In short, DKIM key rotation is a critical aspect of email security and deliverability for large organisations. By using separate DKIM keys, implementing a regular key rotation schedule, and planning the rotation carefully, organisations can maintain the security and deliverability of their emails.
As we will discuss in the following sections, there are various strategies and best practices that organisations can follow to optimise their DKIM key rotation and maintain email deliverability.

Assessing the Risks of Inadequate DKIM Key Rotation

Organisations with high email volume and frequent staff changes are particularly vulnerable to the risks associated with inadequate DKIM key rotation. The consequences of not rotating DKIM keys regularly can be severe, ranging from decreased email deliverability to complete loss of email authentication. A key consideration is the potential for private keys to be compromised, either intentionally or unintentionally, by former employees or malicious actors.
In a hosted setup, such as the one we manage at DMARC Engine, the risk of key compromise can be mitigated through strict access controls and regular audits. However, in self-managed setups, the risk is often higher due to the lack of centralised management and oversight.
For instance, consider an organisation that uses a single DKIM key pair across all its email systems. If an employee with access to the private key leaves the organisation, there is a risk that the key could be used to sign malicious emails, potentially leading to a loss of email authentication and deliverability.
To illustrate this risk, let's consider a real-world example. Suppose an organisation has the following DKIM record:

default._domainkey.example.com. IN TXT "v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCqGKukO1De7zhZj6+H0qtjTkVxwTCpvKe4eCZ0FPqri0cb2JZfXJ/DgYSF6vUpwmJG8wVQZKjeGcjDOL5UlsuusFncCzWBQ7RKNUSesmQRMSGkVb1/3j+skZ6UtW+5u09lHNsj6tQ51s1SPrCBkedbNf0Tp0GbMJDyR4e9T04ZZwIDAQAB" 

If the private key associated with this record is compromised, an attacker could use it to sign malicious emails, potentially leading to a loss of email authentication and deliverability.
In addition to the risk of key compromise, inadequate DKIM key rotation can also lead to decreased email deliverability due to the use of outdated or weak cryptographic algorithms. For example, if an organisation is still using a 1024-bit DKIM key, it may be considered weak by modern standards and could lead to email deliverability issues.
To mitigate these risks, it is essential to implement a regular DKIM key rotation strategy. The frequency of key rotation will depend on various factors, including the organisation's email volume, staff turnover, and security posture. As a general rule, we recommend rotating DKIM keys at least every 6-12 months, or more frequently if the organisation has a high staff turnover or is in a high-risk industry.
In a managed setup, such as the one we offer at DMARC Engine, we can automate the key rotation process, ensuring that DKIM keys are regularly updated and aligned with the organisation's security policies. However, in self-managed setups, the key rotation process can be more complex and requires careful planning and execution to avoid any disruptions to email services.
Ultimately, the key to successful DKIM key rotation is to strike a balance between security and practicality. While it is essential to rotate DKIM keys regularly to maintain email authentication and deliverability, it is also important to consider the potential impact on email services and to plan carefully to avoid any disruptions.
By understanding the risks associated with inadequate DKIM key rotation and implementing a regular key rotation strategy, organisations can help to maintain email authentication and deliverability, even in the face of high email volume and frequent staff changes.
In our experience, a well-planned DKIM key rotation strategy can help to optimise email deliverability and reduce the risk of email authentication issues. For example, we have seen organisations that have implemented regular DKIM key rotation experience a significant reduction in email authentication issues, such as SPF and DMARC failures.
To achieve this, it is essential to centre the DKIM key rotation strategy around the organisation's specific needs and requirements. This may involve rotating DKIM keys more frequently for high-risk email streams, such as those used for financial transactions, while rotating keys less frequently for lower-risk email streams, such as those used for marketing campaigns.
By taking a tailored approach to DKIM key rotation, organisations can help to maintain email authentication and deliverability, while also optimising their email security posture.
In the next section, we will explore the impact of high email volume on DKIM and how organisations can optimise their DKIM configuration to maintain email deliverability in high-volume email environments.

Understanding the Impact of High Email Volume on DKIM

Organisations with high email volume face unique challenges when it comes to DomainKeys Identified Mail (DKIM) key rotation. The sheer number of emails being sent can make it difficult to rotate keys without causing disruptions to email delivery. In our experience at DMARC Engine, we have seen firsthand the impact that high email volume can have on DKIM key rotation. For instance, a large e-commerce company that sends millions of emails per day may need to rotate their DKIM keys more frequently to maintain optimal security, but this can be a complex and time-consuming process.

One of the main concerns for organisations with high email volume is the risk of key exhaustion. When a DKIM key is used to sign a large number of emails, it can become exhausted, leading to a decrease in email deliverability. This is because many email service providers (ESPs) have limits on the number of emails that can be signed with a single key per hour. For example, Gmail has a limit of 500 emails per hour per key. If an organisation is sending more than this limit, they may need to use multiple keys to avoid exhaustion.

; DKIM key record example
"v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCqGKukO1De7zhZj6+H0qtjTkVxwTCpvKe4eCZ0FPqri0cb2JZfXJ/DgYSF6vUpwmJG8wVQZKjeGcjDOL5UlsuusFncCzWBQ7RKNUSesmQRMSGkVb1/3j+skZ6UtW+5u09lHNsj6tQ51s1SPrCBkedbNf0Tp0GbMJDyR4e9T04ZZwIDAQAB"

In a hosted or managed setup, such as the one provided by DMARC Engine, key exhaustion can be mitigated through the use of automated key rotation and management tools. These tools can monitor email volume and rotate keys as needed to prevent exhaustion. However, even with automated tools, organisations with high email volume need to carefully plan and manage their DKIM key rotation to avoid disruptions to email delivery.

Another challenge faced by organisations with high email volume is the need to maintain a large number of DKIM keys. This can be a complex and time-consuming process, especially if keys are being rotated frequently. In our experience, it is not uncommon for large organisations to have hundreds or even thousands of DKIM keys in use at any given time. Managing these keys requires a significant amount of resources and infrastructure, including secure key storage and automated key rotation tools.

; example of a DKIM key storage system
"{
 'keys': [
 {
 'selector': '2022q1',
 'private_key': '-----BEGIN RSA PRIVATE KEY-----',
 'public_key': '-----BEGIN PUBLIC KEY-----'
 },
 {
 'selector': '2022q2',
 'private_key': '-----BEGIN RSA PRIVATE KEY-----',
 'public_key': '-----BEGIN PUBLIC KEY-----'
 }
 ]
}"

To optimise DKIM key rotation for high email volume, organisations should consider implementing a key rotation strategy that takes into account their email volume and frequency of staff changes. This may involve rotating keys more frequently, using multiple keys to sign emails, and implementing automated key rotation and management tools. By carefully planning and managing their DKIM key rotation, organisations with high email volume can maintain optimal email deliverability and security.

In addition to key exhaustion and key management, organisations with high email volume also need to consider the impact of DKIM key rotation on their email authentication and deliverability. When a DKIM key is rotated, it can take some time for email service providers to update their records and begin trusting the new key. During this time, email deliverability may be impacted, and some emails may be flagged as spam or blocked. To mitigate this risk, organisations should ensure that their DKIM key rotation is carefully planned and executed, and that they are monitoring their email deliverability and authentication closely. By doing so, they can quickly identify and address any issues that may arise during the key rotation process.

In our experience, a well-planned and executed DKIM key rotation strategy is critical for maintaining optimal email deliverability and security, especially for organisations with high email volume. By understanding the impact of high email volume on DKIM and taking steps to mitigate the risks associated with key exhaustion, key management, and email authentication, organisations can ensure that their emails are delivered securely and reliably.

Frequent Staff Changes: A Key Consideration for DKIM Management

Frequent staff changes can significantly impact an organisation's DKIM management, particularly when it comes to key rotation. In our experience at DMARC Engine, organisations with high staff turnover rates often struggle to maintain up-to-date DKIM records, which can lead to authentication issues and decreased email deliverability. For instance, when a staff member leaves the organisation, their email account may still be configured to use a DKIM key that is no longer valid or has been revoked.
To mitigate this risk, it is essential to implement a robust DKIM key management process that takes into account staff changes. One approach is to use a centralised key management system that allows administrators to easily revoke and replace DKIM keys when staff members leave the organisation.
In a hosted or managed setup, such as the one we provide at DMARC Engine, this process can be automated to a certain extent. For example, our system allows administrators to set up automated key rotation schedules and receive notifications when a key is about to expire or has been revoked.
However, even with automation, it is crucial to have a clear understanding of the organisation's email infrastructure and DKIM configuration. This includes knowing which email servers and applications are using which DKIM keys, as well as having a process in place for updating DNS records when keys are rotated.
A real-world example of the importance of considering staff changes in DKIM management is the case of a large university that we work with. The university has a high turnover rate of staff and students, which means that email accounts are frequently being created and deleted. To manage this, the university uses a combination of automated key rotation and manual oversight to ensure that DKIM keys are regularly updated and revoked when necessary.
For example, the university's DKIM record might look like this:

default._domainkey.example.ac.uk. 3600 IN TXT "v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC+ytT3lR+QH4bTcJxj9p5d5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t5t

## DKIM Key Rotation Strategies for High-Volume Senders
Organisations with high email volume and frequent staff changes face unique challenges in managing their DKIM keys. A key rotation strategy is essential to maintain email authentication and deliverability, while also minimising the risk of key compromise. In our experience, a well-planned key rotation strategy can make all the difference in ensuring the smooth delivery of emails to recipients' inboxes.

When it comes to high-volume senders, the key rotation strategy must be carefully designed to avoid disruptions to email services. One approach is to use a hierarchical key structure, where a primary key is used for signing emails, and a secondary key is used as a fallback in case the primary key is compromised. For example, a company like Amazon may use a primary key for signing transactional emails, while a secondary key is used for signing marketing emails. 

markdown
; example.com DKIM key record
default._domainkey.example.com. IN TXT "v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC+ycHj4R"

In a hosted or managed setup, the centre of key management is often handled by the provider, which can simplify the process of key rotation. However, it is still essential for organisations to understand the underlying mechanics of key rotation and to work closely with their provider to ensure a seamless transition.

Another important consideration for high-volume senders is the use of key sizes and algorithms. While larger key sizes provide greater security, they can also increase the computational overhead of signing emails. In our experience, a 2048-bit key size using the RSA algorithm provides a good balance between security and performance. 

bash

example of generating a 2048-bit DKIM key using OpenSSL

openssl genrsa -out private.key 2048
openssl rsa -in private.key -pubout -out public.key

When rotating DKIM keys, it is essential to ensure that the new key is properly deployed and tested before retiring the old key. This can be done by publishing the new key in the DNS and verifying that it is correctly signing emails. We recommend using a staging environment to test the new key before deploying it to production.

In addition to key size and algorithm, organisations must also consider the frequency of key rotation. While frequent key rotation can provide greater security, it can also increase the risk of key management errors. In our experience, rotating DKIM keys every 6-12 months provides a good balance between security and manageability. However, this frequency may vary depending on the organisation's specific security requirements and email volume.

Frequent staff changes can also impact DKIM key management, as departing staff members may have access to sensitive key information. To mitigate this risk, organisations should ensure that access to DKIM keys is strictly controlled and that keys are properly revoked when staff members leave the organisation. In a hosted or managed setup, the provider can often assist with key revocation and access control.

To optimise DKIM key rotation, organisations should also consider using automated tools and scripts to simplify the process. For example, a script can be used to generate a new key, publish it in the DNS, and verify that it is correctly signing emails. 

python

example of a Python script to automate DKIM key rotation

import dns.resolver
import OpenSSL

def generate_new_key():

generate a new 2048-bit DKIM key

private_key = OpenSSL.crypto.PKey()
private_key.generate_key(OpenSSL.crypto.TYPE_RSA, 2048)
public_key = OpenSSL.crypto.dump_publickey(OpenSSL.crypto.FILETYPE_PEM, private_key)
return private_key, public_key

def publish_new_key(public_key):

publish the new key in the DNS

dns.resolver.override_system_resolver('/etc/resolv.conf')
answer = dns.resolver.query('default._domainkey.example.com', 'TXT')
for rdata in answer:
print(rdata)

update the TXT record with the new public key

In short, a well-planned DKIM key rotation strategy is essential for organisations with high email volume and frequent staff changes. By using a hierarchical key structure, selecting the right key size and algorithm, and automating the key rotation process, organisations can maintain email authentication and deliverability while minimising the risk of key compromise. In the next section, we will provide a step-by-step guide to implementing DKIM key rotation, including examples and best practices for organisations of all sizes.

## Step-by-Step Guide to Implementing DKIM Key Rotation
Implementing DKIM key rotation is a crucial aspect of maintaining email authentication and deliverability, particularly for organisations with high email volume and frequent staff changes. To centre your DKIM key rotation strategy around these requirements, follow this step-by-step guide. 

First, determine the optimal key rotation frequency for your organisation. This will depend on various factors, including the volume of emails sent, the frequency of staff changes, and the level of security required. As a general rule, it is recommended to rotate DKIM keys every 3-6 months. However, for organisations with extremely high email volumes, such as those in the finance or e-commerce sectors, it may be necessary to rotate keys more frequently, such as every 1-2 months.

Next, generate a new DKIM key pair using a tool such as OpenSSL. The following command can be used to generate a 2048-bit DKIM key pair:

bash
openssl genrsa -out private.key 2048
openssl rsa -in private.key -pubout -out public.key

The resulting public key will be used to create a DKIM TXT record, while the private key will be used to sign outgoing emails.

When creating the DKIM TXT record, it is essential to use a unique selector for each key pair. This will allow you to easily identify and manage multiple key pairs. For example:

dns
default._domainkey.example.com. IN TXT "v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC+yt+5B1E7K3mY9Bx6Q+k4T5H9vZ3uTmzZ7T7hG6Q5a3DY+U7U5K5t4mVHcNzJF7S5g5JU5o5L5o5I5m5Y5n5Z5z5QIDAQAB"

In this example, `default` is the selector, and `example.com` is the domain.

To manage multiple DKIM key pairs, it is recommended to use a hosted or managed DKIM setup, such as DMARC Engine. This will allow you to easily create, manage, and rotate DKIM key pairs, as well as monitor and optimise your email authentication and deliverability. For instance, DMARC Engine provides a user-friendly interface for creating and managing DKIM key pairs, including the ability to set custom rotation schedules and receive alerts when a key pair is nearing expiration.

When implementing DKIM key rotation, it is crucial to consider the impact on your email volume and staff changes. For organisations with high email volumes, it may be necessary to use a load balancer or multiple mail servers to distribute the email traffic. This will help to prevent any single mail server from becoming overwhelmed and reduce the risk of email delivery issues.

In addition, frequent staff changes can pose a challenge for DKIM key management. To mitigate this risk, it is recommended to use a centralised key management system, such as a hosted or managed DKIM setup. This will allow you to easily manage and rotate DKIM key pairs, regardless of staff changes.

To illustrate the importance of DKIM key rotation, consider the following example. Suppose an organisation has a high email volume and frequent staff changes. If the organisation fails to rotate its DKIM keys regularly, it may be vulnerable to security breaches and email delivery issues. For instance, if an employee leaves the organisation and takes their laptop with them, they may still have access to the organisation's DKIM private key. If the key is not rotated, the former employee may be able to use the key to sign emails on behalf of the organisation, potentially leading to security breaches and email delivery issues.

To avoid such issues, it is essential to implement a regular DKIM key rotation schedule. The following is an example of a DKIM key rotation schedule:

markdown
| Selector | Key Pair | Rotation Schedule |
| --- | --- | --- |
| default | Key Pair 1 | Rotate every 3 months |
| backup | Key Pair 2 | Rotate every 6 months |

In this example, the `default` selector uses Key Pair 1, which is rotated every 3 months. The `backup` selector uses Key Pair 2, which is rotated every 6 months.

To automate the DKIM key rotation process, you can use a tool such as cron jobs or a scheduled task. For example, the following cron job can be used to rotate the DKIM key pair every 3 months:

bash
0 0 1 1,4,7,10 * /usr/bin/openssl genrsa -out private.key 2048
0 0 1 1,4,7,10 * /usr/bin/openssl rsa -in private.key -pubout -out public.key

This cron job will generate a new DKIM key pair on the 1st day of January, April, July, and October, which will be used to rotate the existing key pair.

In conclusion to this step-by-step guide, implementing DKIM key rotation is a critical aspect of maintaining email authentication and deliverability. By following these steps and considering the unique requirements of your organisation, you can ensure that your DKIM keys are rotated regularly and securely, reducing the risk of security breaches and email delivery issues. 

It is also worth considering the colour coding of your DKIM key pairs to differentiate between them. For instance, you can use a different colour for each selector, such as blue for the `default` selector and red for the `backup` selector. This will help you to easily identify and manage multiple key pairs.

Finally, to optimise your DKIM key rotation strategy, it is recommended to monitor and analyse your email authentication and deliverability metrics regularly. This will help you to identify any issues or trends and make adjustments to your DKIM key rotation schedule as needed. By following these steps and considering the unique requirements of your organisation, you can ensure that your DKIM keys are rotated regularly and securely, reducing the risk of security breaches and email delivery issues. 

For example, you can use a tool such as DMARC Engine to monitor and analyse your email authentication and deliverability metrics. This will provide you with detailed insights into your email delivery issues and help you to identify areas for improvement. 

In a hosted or managed setup, such as DMARC Engine, you can also set up custom alerts and notifications to inform you when a DKIM key pair is nearing expiration or when there are any issues with your email authentication and deliverability. This will help you to stay on top of your DKIM key rotation schedule and ensure that your email authentication and deliverability are always optimised. 

By following these steps and considering the unique requirements of your organisation, you can ensure that your DKIM keys are rotated regularly and securely, reducing the risk of security breaches and email delivery issues. 

To organise your DKIM key pairs, you can use a spreadsheet or a database to keep track of the selectors, key pairs, and rotation schedules. This will help you to easily manage and rotate your DKIM key pairs, regardless of staff changes or email volume. 

For instance, you can use a spreadsheet to keep track of the following information:

markdown
| Selector | Key Pair | Rotation Schedule | Expiration Date |
| --- | --- | --- | --- |
| default | Key Pair 1 | Rotate every 3 months | 2024-03-01 |
| backup | Key Pair 2 | Rotate every 6 months | 2024-06-01 |

This will help you to easily identify and manage multiple key pairs, as well as keep track of the rotation schedules and expiration dates.

## Real-World Examples of DKIM Key Rotation in Action
Organisations with high email volume and frequent staff changes face unique challenges when it comes to DKIM key rotation. At DMARC Engine, we have worked with numerous customers who have had to navigate these complexities. One such customer, a large financial institution, had to rotate their DKIM keys every 90 days due to regulatory requirements. They had a high email volume, sending over 10 million emails per day, and a large staff with frequent changes. To manage this, they implemented a strategy of using multiple DKIM keys, each with a different selector, and rotating them on a staggered schedule. 
For example, they used selectors such as `selector1`, `selector2`, and `selector3`, each with a corresponding public key published in their DNS as a TXT record, such as:


selector1._domainkey.example.com. IN TXT "v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCqGKukO1De7zhZj6+H0qtjTkVxwTCpvKe4eCZ0FPqri0cb2JZfXJ/DgYSF6vUpwmJG8wVQZKjeGcjDOL5UlsuusFncCzWBQ7RKNUSesmQRMSGkVb1/3j+skZ6UtW+5u09lHNsj6tQ51s1SPrCBkedbNf0Tp0GbMJDyR4e9T04ZZwIDAQAB"

This allowed them to rotate one key while still using the others, ensuring that their email authentication was not disrupted. They also implemented a system to automatically update their DNS records and notify their email service providers of the key changes. 
In a hosted setup, such as the one we provide at DMARC Engine, this process can be largely automated, with the system handling the rotation and publication of new keys, as well as notifying email service providers. However, it is still important for organisations to understand the underlying mechanics and to have a clear strategy in place for managing their DKIM keys. 
Another customer, a large e-commerce company, had a different approach to DKIM key rotation. They used a single DKIM key with a high-bit strength, and rotated it every 180 days. However, they also had a large number of third-party senders, such as marketing automation platforms and customer service software, that needed to be authenticated. To manage this, they implemented a system of subdomain delegation, where each third-party sender had its own subdomain, such as `marketing.example.com` or `support.example.com`. 
Each subdomain had its own DKIM key, which was rotated independently of the main domain key. This allowed the e-commerce company to maintain control over their email authentication while still allowing their third-party senders to operate independently. For example, their DNS records might look like this:


selector._domainkey.example.com. IN TXT "v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCqGKukO1De7zhZj6+H0qtjTkVxwTCpvKe4eCZ0FPqri0cb2JZfXJ/DgYSF6vUpwmJG8wVQZKjeGcjDOL5UlsuusFncCzWBQ7RKNUSesmQRMSGkVb1/3j+skZ6UtW+5u09lHNsj6tQ51s1SPrCBkedbNf0Tp0GbMJDyR4e9T04ZZwIDAQAB"
selector._domainkey.marketing.example.com. IN TXT "v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCqGKukO1De7zhZj6+H0qtjTkVxwTCpvKe4eCZ0FPqri0cb2JZfXJ/DgYSF6vUpwmJG8wVQZKjeGcjDOL5UlsuusFncCzWBQ7RKNUSesmQRMSGkVb1/3j+skZ6UtW+5u09lHNsj6tQ51s1SPrCBkedbNf0Tp0GbMJDyR4e9T04ZZwIDAQAB"

This approach required careful planning and management, but it allowed the e-commerce company to maintain a high level of email authentication and deliverability while still supporting their third-party senders. 
In terms of the colour of the DKIM key rotation strategy, Notably, a staggered approach, such as the one used by the financial institution, can be an effective way to manage the process. This involves rotating different keys at different times, to ensure that there is always at least one valid key in use. For example, an organisation might rotate their `selector1` key in January, their `selector2` key in April, and their `selector3` key in July. 
This approach can help to centre the email authentication process and ensure that it is not disrupted by the key rotation process. However, it does require careful planning and management to ensure that the keys are rotated correctly and that the DNS records are updated accordingly. 
In a managed setup, such as the one provided by DMARC Engine, the system can handle the rotation and publication of new keys, as well as notifying email service providers. This can help to optimise the email authentication process and ensure that it is running smoothly. However, it is still important for organisations to understand the underlying mechanics and to have a clear strategy in place for managing their DKIM keys. 
To illustrate the importance of careful planning and management, consider the example of an organisation that failed to properly rotate their DKIM keys. They had a single key that was used for all of their email sending, and they rotated it every 90 days. However, they failed to update their DNS records correctly, which resulted in a period of several days where their emails were not authenticated. 
This had a significant impact on their email deliverability, with many of their emails being blocked or flagged as spam. The organisation was able to recover from this issue, but it highlighted the importance of careful planning and management when it comes to DKIM key rotation. 
In terms of best practices, it is recommended that organisations use a staggered approach to DKIM key rotation, such as the one described above. This can help to ensure that there is always at least one valid key in use, and that the email authentication process is not disrupted. 
It is also important to ensure that the DNS records are updated correctly, and that email service providers are notified of the key changes. This can help to optimise the email authentication process and ensure that it is running smoothly. 
Finally, Notably, DKIM key rotation is an ongoing process that requires regular attention and maintenance. Organisations should regularly

## Monitoring and Optimising DKIM Key Rotation with Aggregate Reports
To centre our DKIM key rotation strategy around real-world data, we must organise our monitoring efforts around aggregate reports, specifically those provided via the Aggregate Reporting (RUA) mechanism. These reports, typically sent by receiving mail servers to the address specified in the DMARC record, contain a colour-coded summary of email authentication results, including DKIM validation outcomes. By analysing these reports, organisations can optimise their DKIM key rotation to ensure seamless email deliverability, even with high email volumes and frequent staff changes.

A key challenge in monitoring DKIM key rotation is identifying the optimal rotation period. Rotate keys too frequently, and you risk causing authentication failures due to cached public keys; too infrequently, and you expose yourself to potential security risks. Our experience at DMARC Engine suggests that a rotation period of 90 days strikes a good balance between security and deliverability, but this can vary depending on the organisation's specific needs and email volume. For instance, a large e-commerce company with a high volume of transactional emails may prefer a shorter rotation period to minimise the impact of a potential key compromise, while a small business with infrequent email campaigns may opt for a longer period to reduce administrative overhead.

To illustrate the importance of monitoring aggregate reports, consider the following example. Suppose we have a customer with a high-volume email sender, using a DKIM key pair with a 2048-bit private key and a corresponding public key published in their DNS as a TXT record:

markdown
k1._domainkey.example.com. IN TXT "v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCqGKukO1De7zhZj6+H0qtjTkVxwTCpvKe4eCZ0FPqri0cb2JZfXJ/DgYSF6vUpwmJG8wVQZKjeGcjDOL5UlsuusFncCzWBQ7RKNUSesmQRMSGkVb1/3j+skZ6UtW+5u09lHNsj6tQ51s1SPrCBkedbNf0TpeN/WOeWtlOob4EzGCCsDAwAW" ;

If this customer rotates their DKIM key pair every 90 days, they should expect to see a spike in authentication failures in their aggregate reports around the time of rotation, as some receiving mail servers may still be caching the old public key. By closely monitoring these reports, the customer can quickly identify and mitigate any issues, ensuring minimal disruption to their email campaigns.

In a hosted or managed setup, such as the one provided by DMARC Engine, the process of monitoring and optimising DKIM key rotation is significantly streamlined. Our platform automatically collects and analyses aggregate reports from major email providers, providing customers with a centralised dashboard to track their email authentication performance. This includes detailed metrics on DKIM validation outcomes, allowing customers to pinpoint potential issues with their key rotation strategy and make data-driven decisions to optimise it.

One common trade-off in DKIM key rotation is the balance between key size and computational overhead. Larger keys, such as 4096-bit keys, offer greater security but can increase the computational load on sending and receiving mail servers, potentially impacting email delivery speeds. In our experience, a 2048-bit key provides a good balance between security and performance, but this may vary depending on the organisation's specific requirements and infrastructure. For example, a company with a large number of email users and a high-volume email sender may prefer to use larger keys to maximise security, while a small business with limited resources may opt for smaller keys to reduce computational overhead.

To optimise DKIM key rotation, organisations should also consider the impact of frequent staff changes on their email authentication setup. When employees leave or join the organisation, their email accounts and associated DKIM keys may need to be updated or revoked, which can be a time-consuming and error-prone process. By implementing a centralised email authentication management system, such as the one provided by DMARC Engine, organisations can simplify the process of managing DKIM keys and ensure that all email accounts are properly authenticated, even in the face of frequent staff changes.

In addition to monitoring aggregate reports and optimising DKIM key rotation, organisations should also prioritise the security of their DKIM private keys. This includes storing the keys securely, using secure protocols for key exchange, and limiting access to the keys to authorised personnel only. By taking a proactive and data-driven approach to DKIM key rotation, organisations can ensure the security and deliverability of their emails, even in the face of high email volumes and frequent staff changes.

By closely monitoring aggregate reports and adjusting their DKIM key rotation strategy accordingly, organisations can centre their email authentication efforts around real-world data, ensuring seamless deliverability and maintaining the trust of their recipients. As our experience at DMARC Engine has shown, a well-planned and well-executed DKIM key rotation strategy is critical to maintaining email authentication and deliverability, particularly for organisations with high email volumes and frequent staff changes.

## Trade-Offs and Challenges in DKIM Key Rotation: A Practical Perspective
Organisations with high email volume and frequent staff changes face a multitude of challenges when implementing DKIM key rotation, from managing multiple keys and selectors to minimising the impact on email deliverability. A key consideration is the trade-off between security and complexity, as more frequent key rotation can improve security but also increases the risk of errors and misconfiguration. For instance, rotating keys too frequently can lead to a higher likelihood of outdated keys being used by legacy systems or third-party senders, resulting in authentication failures. 

In a hosted or managed setup, such as the one we operate at DMARC Engine, we often see customers struggling to balance the need for frequent key rotation with the practicalities of managing a large number of keys. One approach to mitigate this is to use a hierarchical key structure, where a single root key is used to sign emails, and multiple subordinate keys are used for specific domains or senders. This allows for more granular control over key rotation and reduces the impact of key changes on email deliverability. 

A real-world example of this can be seen in the following DKIM key record snippet:

markdown
default._domainkey.example.com. IN TXT "v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCqGKukO1De7zhZj6+H0qtjTkVxwTCpvKe4eCZ0FPqri0cb2JZfXJ/DgYSF6vUpwmJG8wVQZKjeGcjDOL5UlsuusFncCzWBQ7RKNUSesmQRMSGkVb1/3j+skZ6UtW+5u09lHNsj6tQ51s1SPrCBkedbNf0Tp0GbMJDyR4e9T04ZZwIDAQAB"

In this example, the `default` selector is used to sign emails for the `example.com` domain, and the key is a 2048-bit RSA key. By using a hierarchical key structure, organisations can rotate the subordinate keys more frequently, while keeping the root key stable, to optimise security and minimise the impact on email deliverability.

Another challenge organisations face is managing the impact of staff changes on DKIM key management. When staff members leave or join the organisation, their email accounts and associated DKIM keys need to be updated or revoked. This can be a time-consuming process, especially in large organisations with many staff members. To mitigate this, we recommend implementing a centralised key management system, where all DKIM keys are stored and managed in a single location. This allows for easier rotation and revocation of keys, as well as better tracking and monitoring of key usage.

In addition, organisations need to consider the impact of DKIM key rotation on their email authentication and deliverability. If not done correctly, key rotation can lead to authentication failures, resulting in emails being blocked or marked as spam. To avoid this, organisations should ensure that all email senders, including third-party senders, are aware of the key rotation schedule and have updated their systems accordingly. We also recommend monitoring email authentication and deliverability closely during and after key rotation, using tools such as aggregate reports and email deliverability metrics.

A key metric to monitor is the DKIM authentication rate, which can be tracked using aggregate reports. For example, the following report snippet shows the DKIM authentication rate for a given domain:

markdown
{
"org_name": "example.com",
"date_range": {
"start": "2022-01-01",
"end": "2022-01-31"
},
"dkim": {
"auth_results": [
{
"domain": "example.com",
"selector": "default",
"result": "pass"
},
{
"domain": "example.com",
"selector": "default",
"result": "fail"
}
]
}
}

In this example, the report shows the DKIM authentication results for the `example.com` domain, including the number of passes and fails. By monitoring this metric, organisations can quickly identify any issues with DKIM key rotation and take corrective action to ensure email deliverability.

In conclusion to this section, while DKIM key rotation is an essential aspect of email security, it also presents several challenges and trade-offs for organisations with high email volume and frequent staff changes. By using a hierarchical key structure, implementing a centralised key management system, and monitoring email authentication and deliverability closely, organisations can optimise their DKIM key rotation strategy and ensure the security and deliverability of their emails. As a hosted or managed setup, we centre our approach around these principles, to provide our customers with the best possible email authentication and deliverability outcomes.

## Best Practices for Maintaining Email Authentication and Deliverability
Maintaining email authentication and deliverability is crucial for organisations with high email volume and frequent staff changes, as it directly impacts the centre of their communication strategy. A key aspect of this is optimising DKIM key rotation to prevent email spoofing and ensure consistent deliverability. In our experience, a well-planned DKIM key rotation strategy can make all the difference in maintaining a high level of email authentication. 

For instance, we have seen organisations with high email volume, such as marketing companies, benefit from rotating their DKIM keys every 90 days. This frequency helps to minimise the risk of key compromise while also reducing the administrative burden associated with more frequent rotations. On the other hand, organisations with frequent staff changes, such as universities, may need to rotate their DKIM keys more frequently, such as every 60 days, to account for the higher turnover rate. 

To implement an effective DKIM key rotation strategy, organisations should start by assessing their current email infrastructure and identifying potential vulnerabilities. This includes reviewing their DNS records, such as the example below:

dns
default._domainkey.example.com. IN TXT "v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCqGKukO1De7zhZj6+H0qtjTkVxwTCpvKe4eCZ0FPqri0cb2JZfXJ/DgYSF6vUpwmJG8wVQZKjeGcjDOL5UlsuusFncCzWBQ7RKNUSesmQRMSGkVb1/3j+skZ6UtW+5u09lHNsj6tQ51s1SPrCBkedbNf0Tp0GbMJDyR4e9T04ZZwIDAQAB"

This record shows a DKIM public key, which should be updated regularly to maintain email authentication. 

In addition to rotating DKIM keys, organisations should also ensure that their SPF and DMARC records are up to date and aligned with their email infrastructure. This includes setting up a DMARC record with a reporting address, such as `dmarc@example.com`, to receive aggregate reports and monitor email authentication. For example:

dns
_dmarc.example.com. IN TXT "v=DMARC1; p=none; pct=100; rua=mailto:dmarc@example.com; ruf=mailto:dmarc@example.com; fo=1"
```
This record sets up a DMARC policy with a reporting address, which helps organisations to monitor and optimise their email authentication.

In a hosted or managed setup, such as the one we provide at DMARC Engine, the process of rotating DKIM keys and updating DNS records is automated, which helps to reduce the administrative burden and minimise the risk of human error. Our system also provides real-time monitoring and reporting, which enables organisations to quickly identify and respond to any issues with their email authentication.

To further optimise email deliverability, organisations should also implement a robust monitoring and reporting system, which includes tracking key metrics such as email bounce rates, complaint rates, and spam filter rates. This helps to identify potential issues with email authentication and deliverability, and enables organisations to take proactive steps to address them.

In terms of trade-offs, organisations should weigh the benefits of more frequent DKIM key rotations, such as improved security, against the potential costs, such as increased administrative burden. They should also consider the impact of DKIM key rotation on their email infrastructure, including the potential for downtime or delivery issues.

Ultimately, the key to maintaining email authentication and deliverability is to strike a balance between security, administrative burden, and email infrastructure complexity. By implementing a well-planned DKIM key rotation strategy, and monitoring and optimising their email authentication, organisations can ensure that their emails are delivered consistently and securely, which is essential for maintaining trust and credibility with their customers and stakeholders.

In our experience, organisations that prioritise email authentication and deliverability are better equipped to handle the challenges of high email volume and frequent staff changes, and are more likely to achieve their communication goals. As such, we recommend that organisations make email authentication and deliverability a centre of their communication strategy, and invest in the necessary resources and infrastructure to support it.

Share

See where your domain stands today

Run a free DMARC scan, then let us take you to enforced p=reject with no email outage.