Migrating to 2048 Bit DomainKeys Identified Mail (DKIM)

Twilio SendGrid now uses 2048 Bit DomainKeys Identified Mail (DKIM) to provide stronger security and protection. Existing domain authentication configurations are not changing automatically but if you wish to enhance your security from your existing setup follow this guide.

If you created your first domain authentication after May 2021, you already have a 2048 DKIM key.

How can I tell if I have 1024 bit DKIM keys or 2048 bit DKIM keys?

You can use this online tool to easily check their key length. The tool asks for the selector and domain. If the customer’s DKIM key was at s1._domainkey.example.com, then you would enter “s1” in the selector field and “example.com” in the domain field.

To migrate to 2048 Bit DKIM Keys:

  1. Log into your SendGrid account and navigate to Settings.
  2. Select Sender Authentication and then click Authenticate Your Domain.
  3. Continue through the domain authentication process. When you get to the second page, you will need to use a custom selector that differs from the default “s1” that SendGrid uses under the advanced settings. You should use a unique value (eg. 'abc').
  4. Delete the old domain authentication once you have verified the new one.

For more information about DKIM records, go to the DKIM Records Explained page.

Rate this page:

Need some help?

We all do sometimes. Get help now from the Twilio SendGrid Support Team.

Running into a coding hurdle? Lean on the wisdom of the crowd by browsing the SendGrid tag on Stack Overflow or visiting Twilio's Stack Overflow Collective.

Thank you for your feedback!

Please select the reason(s) for your feedback. The additional information you provide helps us improve our documentation:

Sending your feedback...
🎉 Thank you for your feedback!
Something went wrong. Please try again.

Thanks for your feedback!

thanks-feedback-gif