Remove the public key TXT record from DNS immediately. The compromised key can no longer be used to verify signatures. Generate a new key pair, publish the new public key under a new selector, and reconfigure your mail server to sign with the new private key. This is why key rotation on a schedule (annually or more) is recommended.
All questions