Solo ads sellers / Blog / DKIM algorithms

Solo ads blog

An obsolete DKIM key is a reason to pause the solo ad

Answer An obsolete DKIM algorithm is a reason to pause the solo ad. RFC 8301, published in January 2018, says rsa-sha1 is no longer acceptable for DKIM signatures. A domain that still signs that way is offering a retired check. Fix the key before you argue about the swipe. This note will not invent a bit length the specification was not opened to quote.

Cream stationery and a teal accent on a dark navy desk
An old key is a reason to pause.

The note that started this: RFC 8301, Cryptographic Algorithm and Key Usage Update to DKIM, RFC 8301, January 2018.

By now the quote has a from-name, a signer, and a p= value. The remaining embarrassment is a signature that uses an algorithm the update retired years ago. It still verifies in the narrow sense that the math runs. It does not meet the update. Receivers are allowed to stop trusting it. A buyer should stop trusting the order until the header shows a current choice.

RFC 8301 is a short update to the DKIM algorithm and key guidance. The sentence to keep is the conservative one. Be conservative. rsa-sha1 is no longer acceptable. The document also talks about key size. This desk will not recite a minimum number of bits from memory and call it a quotation. If you operate the domain, open the RFC and follow it. If you are buying a send, you do not need the integer. You need the seller to show the algorithm tag on a live signature, and to replace the signature when the tag is the retired one.

What does RFC 8301 say about old DKIM algorithms?

RFC 8301, published in January 2018, updates DKIM so that rsa-sha1 is no longer an acceptable signing algorithm. A signature that still uses it is using a retired choice.

The tag in the header is a=. A value that says rsa-sha1 is the stop sign. A value that says rsa-sha256 is the ordinary modern choice the update points toward. You are not performing a cryptanalysis in the quote. You are reading a word. Sellers who have not rotated a key since the tool was first installed can still be emitting the old word. The install felt permanent. The specification moved.

Age of the document is not a reason to ignore it. January 2018 is long enough ago that a seller in 2026 does not get to call the change news. If you buy solo ads, a sha1 signature is a reason to believe the rest of the authentication story is also unexamined. People who rotate keys tend to know their d= domain. People who do not tend to discover both problems on the day a mailbox starts rejecting them.

Is a weak key a copywriting problem?

No. The words in the solo ad do not repair the key. Pause the send until the domain signs with an acceptable algorithm and a key the operator can explain. Then look at the copy.

A buyer who rewrites the subject line while the signature is obsolete is decorating a message the mailbox may already distrust. The distrust is not about the adjective in the headline. It is about a cryptographic choice the operator left in place after the standard told them to stop. Rewrite the signature first. The swipe can survive a week. A domain that signs badly on a large drop collects a reputation problem the swipe cannot unsay.

If you sell the send, rotate the key on a quiet day. Publish the new selector. Sign a seed to yourself. Read a=. Then take the buyer's order. Doing it backwards means the buyer's offer is the test, and the test fails in front of the list. That is an expensive way to read an eight-year-old RFC.

What should a buyer ask to see?

Ask for the a= value on a live DKIM signature. If it names sha1, stop. Ask the seller to resign with a current algorithm before any money moves. Do not accept a promise that the key is long enough without the header.

Length without the algorithm is half a sentence. Algorithm without a live header is a claim. You want the header. The same seed address you have been asking for all month can carry this tag. One message answers d=, a=, and the From domain together.

Hold the price until that message exists. Safe solo ads sellers can forward a header. An obsolete key is not a negotiation. It is a pause.