RFC 4871 required the use of a DKIM RSA key length of at least 1,024 bits “for long-lived keys,” but also required that verifiers continue to support shorter keys. And many shorter keys were in common use even five years later, when Google’s 512 bit DKIM key was cracked and used to send spoofed email […]
