Turning on DKIM for Google Workspace happens in the Admin console, not in your domain's DNS panel. Go to Apps, then Google Workspace, then Gmail, then Authenticate email. That screen generates the key and gives you the exact DNS record to publish.
Google recommends generating a 2048-bit key wherever your domain host supports it, stating in its own documentation that longer keys are more secure than shorter ones. The generated record publishes as a TXT record at google._domainkey, the fixed selector Google Workspace uses.
google._domainkey with your DNS host.Authentication resolves in minutes against a DNS lookup, while reputation and engagement take an afternoon or longer to read. It is the first of the six checks I run on any deliverability problem for exactly that reason: rule out what is fast before what is slow, not what feels most likely.
Google states this warning can persist for up to 48 hours after a correct record is added, purely from propagation delay, and should be ignored if the record itself is confirmed correct.
Google recommends 2048-bit wherever your DNS host supports the longer TXT value, stating explicitly that longer keys are more secure.
DKIM alone is not enough for Google's own bulk-sender requirements above 5,000 messages a day to personal Gmail accounts, which require SPF, DKIM and DMARC together with From-domain alignment, not any one of the three in isolation.