Ispconfig DKIM keys rotation

Discussion in 'General' started by ArekSmig, May 19, 2026 at 1:48 PM.

  1. ArekSmig

    ArekSmig New Member

    How do I rotate DKIM keys without any downtime for my email service? We use a single-server setup with just a DNS client, and the DNS servers are located at the service provider infrastructure. Ispconfig itself does not support key rotation, at least I don't see such an option.
     
  2. Taleman

    Taleman Well-Known Member HowtoForge Supporter

    If ISPConfig controls your DNS servers, then ISPConfig copies the DKIM keys to DNS.
    When DNS servers are located outside of ISPConfig, you need to copy the DKIM key to DNS primary server.
    I believe ISPConfig does not have automatic key rotation. I'n not convinced it would do any good to create new key unless old private key has somehow been leaked to malicious party.
     
    ahrasis likes this.
  3. ArekSmig

    ArekSmig New Member

    The need for DKIM key rotation stems from the Data Protection Officer's guidelines. All keys in use are to be changed at least every six months. I need to organize this somehow.
     

Share This Page