Email · appears in CAIQ, SIG, SOC 2
Are DKIM keys published with sufficient key strength (>= 1024 bits)?
DKIM signs outbound mail so receivers can detect tampering. Missing selectors or rotated-away keys break DMARC alignment and let receivers downgrade trust (ISO 27001 A.8.24).
How to answer this
Whichever verdict your domain earns, this is the wording to put in the response box. Reviewers mark an answer down for vagueness more often than for a "No", so say which state you are in and what evidences it.
- Yes
- At least one DKIM selector is published with adequate key strength
- Partial
- DKIM selectors are published but with key-strength concerns
- No
- No DKIM selectors were found at the common selector names
Controls this evidences
| Framework | Control | Why it maps |
|---|---|---|
| SOC 2 | CC6.7 | DKIM signing proves mail authenticity end-to-end. |
| ISO 27001 | A.8.24 | — |
| NIST 800-53 | SC-8 | — |
Domain Posture is not an audit and does not replace an auditor. See methodology v1 for how each verdict is reached.
When a "Yes" stops being true
All DKIM selectors removed or rotated away, or key strength dropped below the threshold.
That is the whole problem with answering a questionnaire from a screenshot: the answer was true the day you took it. A signed evidence pack is dated, and a schedule re-checks it so you find out before your reviewer does.