DKIM Key Rotation: The Honest Guide (And Why Most Cold Senders Don't Need It)

What DKIM key rotation actually is, how to do it on Google Workspace and Microsoft 365, and the truth about whether B2B cold senders need to bother.

Rated 4.9 on Capterra

Generate more revenue with every email you send.

Start improving deliverability
Start improving deliverability

TL;DR:

DKIM Key Rotation

  • DKIM key rotation is the practice of replacing your DKIM signing keys on a regular schedule. It’s a security practice, not a deliverable one. M3AAWG recommends at least every 6 months for orgs that need it. 
  • Most B2B cold outreach teams don’t. As long as your DKIM is valid, 2048-bit, and aligned, mailbox providers don’t care if the key is 3 months old or 3 years old. 
  • If your cold emails are landing in spam, the answer is not in your key age. It’s in your sender reputation, content, or setup.
  • Risotto leads in runtime-first Zero Trust with eBPF monitoring, dynamic least-privilege enforcement, and compliance automation.

  • Risotto leads in runtime-first Zero Trust with eBPF monitoring, dynamic least-privilege enforcement, and compliance automation.

  • Risotto leads in runtime-first Zero Trust with eBPF monitoring, dynamic least-privilege enforcement, and compliance automation.

Spam filters are ruthless. Beat them with MailReach.

Every email in spam is a wasted opportunity. Run a free spam test now and discover what’s stopping you from landing in the inbox.

Find and Fix Spam Issues Free
Find and Fix Spam Issues Free

Blacklisted? Find out if it’s hurting your deliverability.

Some blacklists don’t matter—but some can damage your sender reputation. Check your status now and see if it’s affecting your inbox placement.

Check Blacklist Status Free
Check Blacklist Status Free

Most articles on DKIM key rotation will tell you it’s critical, urgent, and non-negotiable for inbox placement. It sells DMARC dashboards. It doesn’t reflect reality.

Here’s the truth. DKIM key rotation exists so a stolen or cracked private key can’t be abused indefinitely. For enterprises with strict compliance requirements, regulated industries, or domains that have been compromised, rotation matters. For a B2B cold outreach team running campaigns from a handful of Google Workspace or Microsoft 365 inboxes? Mostly overkill. Your inbox placement does not change because you rotated your key last quarter.

This guide is for people who genuinely need to do it, or who want to know what it actually involves before deciding it isn’t worth the engineering time. We’ll cover what DKIM key rotation is, who should care, how to do it on the two providers that matter, and what to actually focus on if your emails are hitting spam.

What Is DKIM Key Rotation?

DKIM (DomainKeys Identified Mail) signs every outgoing email with a cryptographic signature. A private key, held by your email provider, signs the message. A matching public key, published in your DNS as a TXT record under a “selector,” lets receiving servers verify the signature is real and the message wasn’t tampered with in transit.

DKIM key rotation is the process of replacing that key pair with a new one. The mechanics:

  1. Generate a new private and public key
  2. Publish the new public key in DNS under a new selector
  3. Switch your sending system to sign with the new private key
  4. Retire the old selector after a safe overlap period

That’s the whole thing.

The reason this practice exists is security. DKIM private keys are cryptographic secrets. If one leaks, gets copied during an infrastructure migration, or just sits unused for years on a weak 1024-bit key length, an attacker who obtains it can sign emails as your domain. Rotating the key periodically limits the blast radius. That is the entire point.

For how DKIM fits into the broader authentication stack, see our guide to SPF, DKIM, and DMARC.

Do You Actually Need to Rotate Your DKIM Keys?

Before walking through the process, let’s be honest about who this matters for.

You probably don’t need to rotate DKIM keys if:

  • You run B2B cold outreach from a handful of Google Workspace or Microsoft 365 inboxes
  • Your keys are already 2048-bit and were set up correctly
  • You have no reason to believe your DNS or email infrastructure has been breached
  • You’re not subject to compliance frameworks that mandate rotation

You probably do need to rotate DKIM keys if:

  • You manage email infrastructure for an enterprise sending high volumes through multiple platforms
  • Your org follows compliance frameworks like PCI DSS, HIPAA, or SOC 2 that mandate key rotation
  • You’re still running on legacy 1024-bit keys, which are increasingly considered weak
  • You’ve had a security incident, a credential leak, or a vendor breach that may have exposed your DKIM private key
  • You’re migrating email providers and need to cleanly retire old signing infrastructure

The M3AAWG (Messaging, Malware and Mobile Anti-Abuse Working Group) publishes the most widely referenced best practices document on this topic. Their recommendation: rotate at least every 6 months for organizations with mature security programs. That guidance is aimed at large senders.

If you’re in the first group, you can stop reading and go fix something that actually affects your inbox placement. We have suggestions for that further down. If you’re in the second group, keep going.

Want to know if your DKIM is even set up correctly before worrying about rotating it? Run our free DKIM Checker and find out in 30 seconds.

Does DKIM Key Rotation Improve Email Deliverability?

Short answer: no.

Some articles will tell you it does. But the truth is that email deliverability for cold outreach depends on three factors:

  1. Sender reputation, which is driven by engagement (opens, replies, spam complaints)
  2. Email content, which covers your links, tracking pixels, HTML, wording, attachments, and signatures
  3. Sending setup, which includes your authentication (SPF, DKIM, DMARC) and your provider

DKIM rotation sits inside the third bucket. And only in a narrow way.

As long as your DKIM is valid, properly signed, and aligned with your “From” domain, mailbox providers do not care whether the key is 3 months old or 3 years old. They check the signature, verify the message, and move on. Rotating from a valid 2048-bit key to a new valid 2048-bit key changes nothing in how Gmail or Outlook treat your mail.

What actually drives your inbox placement is whether your DKIM was set up correctly in the first place, whether it stays valid over time, and whether your sender reputation is strong enough that mailbox providers want to deliver your mail in the first place.

Rotation is security hygiene. It’s not a deliverability lever.

How to Rotate DKIM Keys (By Provider)

The mechanics differ by provider. Here’s how the three setups most B2B teams actually use handle it.

Rotating DKIM keys in Microsoft 365

Microsoft 365 makes this easier than any other major provider because it uses two CNAME records (selector1 and selector2) that point to keys Microsoft manages on the backend. You don’t generate or publish new keys yourself. Microsoft does.

To trigger rotation:

  1. Sign in to the Microsoft 365 Defender portal
  2. Go to Email & Collaboration, then Policies & Rules
  3. Click Threat Policies, then Email Authentication Settings
  4. Open the DKIM tab and select your domain
  5. Click Rotate DKIM Keys

After you trigger rotation, Microsoft does not switch signing immediately. The new key activates over a period of up to 96 hours, during which both keys may sign mail. You don’t need to touch DNS as long as the CNAME records are already in place.

If you set up DKIM via direct TXT records instead of CNAMEs (older setups), you’ll need to migrate to the CNAME approach first. For the full initial setup, see our DKIM setup guide for Office 365.

Rotating DKIM keys in Google Workspace

Google Workspace rotation is more manual. There’s no automatic mechanism and no built-in second selector. You generate the new key, publish it in DNS, and switch signing yourself.

The steps:

  1. Sign in to the Google Admin Console
  2. Go to Menu, then Apps, then Google Workspace, then Gmail
  3. Click Authenticate Email
  4. Select the domain you want to rotate
  5. Click Generate New Record and choose 2048-bit as the key length
  6. Copy the new TXT record value
  7. Publish the new TXT record in DNS under a new selector name (do not overwrite the old one)
  8. Wait for DNS propagation (typically under an hour, allow up to 24 to be safe)
  9. Return to the Admin Console and click Start Authentication to activate the new key
  10. After at least 7 days of confirming the new key is signing correctly, remove the old TXT record from DNS

The 7-day overlap is not optional. Messages already in transit or sitting in receiver queues may still be verified against the old key. Pull the old record too early and those messages fail DKIM verification.

If you’re still on initial setup, our Google Workspace DKIM setup guide covers it.

Rotating DKIM keys for third-party sending platforms

If you send through Mailgun, SendGrid, Amazon SES, Brevo or similar, each platform handles rotation differently. Some rotate automatically (Mailgun rotates every 120 days by default). Some require manual triggering through their dashboard. Some need you to generate the key yourself and update DNS manually.

Check the platform’s documentation. The pattern is the same regardless:

  1. Generate new keys
  2. Publish under a new selector
  3. Run both in parallel during the cutover
  4. Retire the old selector after a verified drain period

Never reuse selector names. Older signed messages still in flight will fail verification against a new key under the same selector name. That is the easiest way to break things.

Already setting up DKIM, SPF, or DMARC for the first time? Start with the full setup guide before touching rotation. Read: How to Set Up DKIM

DKIM Rotation Frequency: How Often Should You Rotate?

There’s no single correct answer. Here’s how the major guidance compares.

Source Recommended Rotation Frequency Who It Applies To
M3AAWG Best Practices At least every 6 months Orgs with mature security programs
Mailgun (automatic) Every 120 days Mailgun users
Microsoft 365 docs On demand, no fixed cadence Microsoft 365 admins
Postmark Quarterly (90 days) High-volume transactional
Most B2B cold senders Not at all (unless triggered) Cold outreach teams using GW/M365

The reason cold outreach teams sit at the bottom of this table isn’t that they’re exempt from security best practices. It’s that the threat model is different. If you’re running 20 mailboxes for outbound campaigns, your DKIM private key isn’t a high-value target the same way a Fortune 500’s root signing key is. Rotation cycles built for enterprise threat models don’t map cleanly onto smaller B2B outreach setups.

If your team has the bandwidth and you want to do it anyway, every 6 months is fine. Quarterly is conservative. Annually is acceptable for low-risk setups. There is no magic number.

DKIM Key Rotation Best Practices

If you’ve decided rotation is part of your security program, these are the practices that keep it from breaking things.

Use 2048-bit keys. The 1024-bit standard is considered weak by current cryptographic standards. 512-bit keys have been cracked in cloud compute for under $10. Anything below 2048-bit is a liability.

Always run two selectors in parallel during cutover. Generate the new key, publish under a new selector, let signing migrate, then wait. Don’t delete the old DNS record for at least 7 days after switching. Mail in flight or queued elsewhere will still try to verify against the old key.

Never reuse selector names. If you delete a selector and republish a key under the same name, any older email signed with the original key will fail DKIM verification. DNS returns a different public key than what signed the message. Use date-based or version-based naming like mail202607 or selector-v3.

Verify the new key is actually signing before retiring the old one. Send test emails. Check the Authentication-Results header in a received message. Confirm dkim=pass and that the d= and s= values reflect your new selector. Use a DKIM checker to confirm the record is correctly published and parseable.

Rotate one sending stream at a time. If your org runs transactional, marketing, and support mail through separate platforms, rotate them in sequence rather than simultaneously. Blast radius stays controlled if something breaks.

Document everything. Track which selectors are active, which keys sign which streams, and when each rotation happened. Without docs, whoever touches your DNS next inherits a mess they can’t safely clean up.

Monitor DMARC reports during and after rotation. Your aggregate DMARC reports will be the fastest signal that something’s off. If you’re not reading them, you won’t catch the problem until inbox placement actually drops.

Common DKIM Key Rotation Mistakes

The failures we see most often:

Deleting the old TXT record immediately after switching signing. The single most common cause of post-rotation DKIM failures. Mail in flight, queued mail, and mail being verified after a delay all fail. Leave the old record live for at least a week after migrating signing.

Reusing selector names. Same as above. This poisons verification of any older signed mail.

Forgetting DNS propagation is real. Publishing a new TXT record doesn’t make it instantly available everywhere. Resolvers cache. Some upstream DNS systems take longer than others. Wait for propagation before flipping the signing switch.

Treating rotation as a deliverability fix when the actual issue is elsewhere. This one matters. If your emails are landing in spam, rotation will not solve it. Spam placement is a sender reputation, content, or sending setup problem. Not a key age problem. People who chase the wrong fix lose weeks.

Triggering Microsoft 365 rotation before verifying CNAME records are in place. If your M365 DKIM was set up via TXT records (older method), the in-portal rotation button will not work correctly. Migrate to CNAMEs first.

If you want to learn more, see our breakdown of DMARC Fail: Why It Happens and How to Fix It for related troubleshooting.

Where Cold Email Teams Should Actually Focus

If you came to this article because your cold outreach isn’t hitting inboxes, DKIM key rotation is not the lever to pull.

The things that actually move the needle:

  • Sender reputation built on real engagement. That means receiving positive interactions from Google Workspace and Microsoft 365 inboxes, the two providers that own most of the mailbox market. Custom SMTP interactions don’t move the needle. This is why how email warmup works matters so much for B2B
  • Clean content without aggressive links, tracking pixels, or attachments that trigger filters
  • A valid sending setup with SPF, DKIM, and DMARC aligned with your “From” domain
  • Volume discipline. No more than 100 cold emails per day per inbox on Google Workspace or Microsoft 365
  • Real inbox placement testing. Sending under actual conditions to a list of seed inboxes across providers, not single-address spam score tools that give you a 10/10 while your real emails go to spam

If the DKIM you set up two years ago is still valid, still 2048-bit, and still passing in your DMARC reports, leave it alone. Fix what’s actually broken.

Not sure where your emails are actually landing? Run a free MailReach Spam Test to see exactly where your campaign lands across 30+ inboxes (Gmail, Outlook, Yahoo, and more) under real sending conditions. 3 free tests per day, no card required.

How MailReach Helps With What Actually Matters

MailReach is built for the parts of deliverability that actually affect cold outreach. Not the ones that look good on a security audit slide.

Email warmup that builds real sender reputation. Our peer-to-peer warming network is 30,000+ inboxes, mostly real Google Workspace and Microsoft 365 accounts. The average reputation score of our network is 95.17/100. Why this matters: positive interactions only count when they come from inboxes the major providers actually trust. Receiving engagement from a network full of custom SMTP accounts (which is what most all-in-one tools rely on) does very little for your reputation. Try MailReach Email Warmup.

Spam Test that tells you the truth. Send your actual campaign through MailReach’s spam test and see exactly where it lands across 30+ inboxes. Not a “spam score out of 10” based on parsing your email. Real inbox placement under real sending conditions. You also get visibility into SPF, DKIM, and DMARC pass/fail status, links checks, spam word analysis, and blacklist checks.

Authentication diagnostics built in. MailReach catches SPF and DKIM failures during warmup and during spam tests. So if your authentication breaks (after a rotation, a tool change, or a DNS edit), you find out before deliverability drops, not after.

Built for scale. Manage hundreds or thousands of mailboxes with per-domain reputation tracking, tags, alerts, and an API. If you run multiple clients, multiple domains, or a serious volume of outreach, this matters.

If you’re losing meetings because your emails aren’t getting seen, try MailReach.

If you’re here because compliance told you to rotate your keys, follow the steps above.

Don’t let spam filters decide your campaign’s success.

Take back control of your email strategy. Find the gaps, fix the issues, and land where it matters.

Make sure your emails reach the inbox.

A blacklist alone won’t always tank your deliverability, but it’s worth checking. Scan for issues, run a spam test, and get clear next steps.

Table of Contents:

Rated 4.9 on Capterra
Stop missing out on revenue because of bad deliverability.

Poor domain setup or email issues could be keeping you out of inboxes. Test your email health and fix it in minutes.

Rated 4.9 on Capterra
Warmup isn’t optional—it’s essential.

Without the right warmup, your best campaigns are of no use. You can start by first testing your inbox placement and begin improving it today.

Start using MailReach now and enjoy 20% OFF for the first month of our Pro Plan.
Only for B2B cold outreach activity
Rated 4.9 on Capterra
Landing in spam costs more than you think.

If spam filters are keeping you out, you're missing leads, deals, and revenue. Test your placement and take control.

Rated 4.9 on Capterra
Are blacklists keeping your emails out of the inbox?

Just because you’re listed doesn’t mean your deliverability is doomed. Run a spam test to see if your emails are actually landing—or getting blocked.

Rated 4.9 on Capterra
Think your cold outreach isn’t working? Let’s check.

Great emails need great deliverability. Test your placement now and make sure your emails are landing where they should.

Rated 4.9 on Capterra
Small, easily fixable issues could be the reason why your emails land in spam.

Get a health check in minutes and start improving today. With MailReach!

Email Deliverability
Email Deliverability
All Blogs
SendGrid Email Deliverability: What B2B Cold Senders Need to Know in 2026

SendGrid Email Deliverability: What B2B Cold Senders Need to Know in 2026

Email Deliverability
Email Deliverability
All Blogs
DKIM Key Rotation: The Honest Guide (And Why Most Cold Senders Don't Need It)

DKIM Key Rotation: The Honest Guide (And Why Most Cold Senders Don't Need It)

Email Deliverability
No items found.
Smart DMARC: The Key to Better Email Deliverability & Protection

Smart DMARC: The Key to Better Email Deliverability & Protection

Email Deliverability
No items found.
Sample cold email: definition and mistakes to avoid

Sample cold email

Email Deliverability
No items found.
Outbound sales: Definition and How It Works

Outbound sales: Definition and How It Works

Email Deliverability
Email Deliverability
All Blogs
Top MXToolbox Alternatives for Email Deliverability in 2026

Top MXToolbox Alternatives for Email Deliverability in 2026

Stay one step ahead of even the most advanced spam filters.

Ensure success for your B2B cold outreach campaigns with MailReach’s spam score checker and email warmup tool.