On Tue, Oct 10, 2017 at 9:03 AM, Philip Paeps <phi...@trouble.is> wrote:

>
> Are there any published recommendations on how frequently one should
> rotate DKIM keys?
>

Yes:
https://www.m3aawg.org/documents/en/m3aawg-dkim-key-rotation-best-common-practices

There's an update coming soon but the frequency recommendations don't
change.


> I've been rotating mine annually.  I use my DNSSEC KSK rollover reminders
> to remind me to roll my DKIM keys too (and I've just noticed I have been
> forgetting to roll some of them for a while).
>
> I would not be surprised if rolling keys at all puts us firmly in a
> statistically insignificant minority. :)


M3AAWG is also working on an email authentication practices survey that
will be coming out soon too.

--Kurt Andersen
_______________________________________________
mailop mailing list
mailop@mailop.org
https://chilli.nosignal.org/cgi-bin/mailman/listinfo/mailop

Reply via email to