“Three decades ago, breaking a 512-bit RSA public key was a feat achievable only with a supercomputer. Today, it’s possible to do so in just a few hours for less than US$8 on a cloud server.”
A 512-bit DKIM key fell in 86 hours on an $8 cloud server. Over 1,700 domains in the top million still publish keys shorter than 1,024 bits. Yahoo Mail, Mailfence, and Tuta accepted the forged signature. RFC 8301 retired short keys in 2018 and nobody rotated.