Questions tagged [dkim]

DomainKeys Identified Mail is a scheme for signing and verifying email messages to confirm that that the source hasn't been forged, and is typically implemented by MTAs. The source MTA adds a header to the message body containing a signature, and the destination MTA verifies this signature against a key retrieved from DNS.

DomainKeys Identified Mail (DKIM) is an email authentication method designed to detect forged sender addresses in emails (email spoofing), a technique often used in phishing and email spam.

DKIM allows the receiver to check that an email claimed to have come from a specific domain was indeed authorized by the owner of that domain.[1] It achieves this by affixing a digital signature, linked to a domain name, to each outgoing email message. The recipient system can verify this by looking up the sender's public key published in the DNS. A valid signature also guarantees that some parts of the email (possibly including attachments) have not been modified since the signature was affixed.[2] Usually, DKIM signatures are not visible to end-users, and are affixed or verified by the infrastructure rather than the message's authors and recipients.

The first version of DKIM synthesized and enhanced Yahoo!'s DomanKeys and Cisco's Identified Internet Mail specifications. It was the result of a year-long collaboration among numerous industry players, during 2005, to develop an open-standard e-mail authentication specification. Participants included Alt-N Technologies, AOL, Brandenburg InternetWorking, Cisco, EarthLink, IBM, Microsoft, PGP Corporation, Sendmail, StrongMail Systems, Tumbleweed, VeriSign and Yahoo!. The team produced the initial specification and several implementations. It then submitted the work to the IETF for further enhancement and formal standardization.

603 questions
12
votes
3 answers

DMARC Alignment: Enforce messages pass BOTH SPF and DKIM

Is there a way to enforce DMARC to fail/reject mail that doesn't pass BOTH DKIM and SPF? We have been narrowing the number that are failing, but there are some domains in our aggregate (rua) report that are passing just DKIM and we would rather that…
11
votes
4 answers

Why is my opendmarc failing pretty much everything that comes through?

I have this domain for which I set up SPF, DKIM, and DMARC stuff. Let's pretend the domain is example.com which has the following entries in its DNS zone: example.com. 600 IN MX 1 mail.morpheu5.net. example.com. …
Morpheu5
  • 259
  • 4
  • 18
11
votes
2 answers

Mail with DKIM Signature gets T_DKIM_INVALID flag by SpamAssassin

I've installed a Debian (jessie) box with postfix and spamassassin. Configured and everything works fine. Except receiving mails with DKIM signatur will produce a flag T_DKIM_INVALID even if the signature is valid. See log example below. After that,…
High Ball
  • 478
  • 4
  • 11
11
votes
2 answers

Publishing long domain key records in bind9

I am setting up a mail system based on exim4. This system implements DKIM signing and checking (among other things). Signing seems to work without problems but checking doesn't work and exim4 complains about the syntax of my TXT records which…
alxgomz
  • 1,630
  • 1
  • 11
  • 14
11
votes
2 answers

How did spammer spoof emails with my google apps domain (it even has DKIM!)

I have been getting a lot of bounce-backs lately. I thought my google apps account has been compromised, but there is no activity on my apps account, and there is certainly no malicious user that I can see. Since the email is always send from some…
Sam
  • 965
  • 1
  • 7
  • 8
11
votes
3 answers

record DKIM on IONOS makes sense?

If I am sending mail through SMTP, I understand that it is IONOS who signs those emails, right? I would like to add the DKIM header to my emails. I know that it is necessary to publish a CNAME record with the public key but if I don't use a…
Diego
  • 113
  • 1
  • 4
10
votes
2 answers

DMARC and DKIM alignment with multiple DKIM signatures

If an email contains multiple DKIM signatures as it's forwarded, how does DMARC process the DKIM alignment check? Does ANY passing DKIM signature d= parameter have to match Header From? or Does the first (or last) DKIM signature d= parameter have to…
Novox
  • 474
  • 1
  • 9
  • 27
10
votes
4 answers

SPF + DKIM + DMARC with Gmail account and external mail server

I,m using gmail with own domain (Google Apps) for my project. Now I want to add external mail server for sending notifications for users. Gmail doesn't give private keys for DKIM and if keys will be generated on external mail server, in case strict…
cptBuggy
  • 101
  • 1
  • 1
  • 4
10
votes
4 answers

no signing table match in OpenDKIM

I have OpenDKIM installed on CentOS. I am using postfix as MTA and dovecot for IMAP/POP3. Now the problem is am trying to setup DKIM for my domain. The mails are send from a sub domain mail.example.com. The issue is that mails are not being signed…
Amal
  • 301
  • 1
  • 2
  • 10
10
votes
3 answers

Why is my email failing Gmail's DKIM test?

I have a message that was rejected by Gmail, I don't know why. It passes SPF. We aren't using DKIM. Do I need to set up DKIM? I am in control of "example.com". Our mail server is "server.example.com" (hosted at bluehost) Our SPF record is v=spf1 +a…
nielsbot
  • 223
  • 1
  • 3
  • 9
10
votes
1 answer

How do I use OpenDKIM with multiple domain names on a single server?

How do I use OpenDKIM with multiple domain names on a single server? I own 3 domain names, and I have a single server that's running postfix for sending email. How do I use OpenDKIM? Can I use the same keyfile for all 3 domain names? Do I have to…
user18233
10
votes
2 answers

SPF hardfail and DKIM failure when recipient has e-mail forwarding

I configured hardfail SPF for my domain and DKIM message signing on my SMTP server. Since this is the only SMTP server that should be used for outgoing mail from my domain, I didn't foresee any complications. However, consider the following…
Belmin Fernandez
  • 10,799
  • 27
  • 84
  • 148
10
votes
1 answer

Are there any pitfalls to DKIM?

We are considering implementing DKIM, the pros seem pretty obvious. Are there any cons? I know this is a bit vague and possibly subjective so I will accept what seems to me to be the most complete answer when 24 hours have transpired with no new…
Aaron Bush
  • 237
  • 1
  • 2
  • 10
10
votes
2 answers

How does DKIM work when sending emails from multiple sources/servers?

So if I'm understanding DKIM correctly, it basically is a public/private key type of service. However, how does this work if you send emails from multiple servers/sources? For instance, I have a split domain where I send some emails (under the…
Marc NJ
  • 111
  • 1
  • 4
9
votes
2 answers

DKIM not signing with alias addresses - not internal, not authenticated

I have postfix, dovecot, opendkim and postsrsd installed. I am trying to forward mail from alias@example.com to myemail@gmail.com, and have them signed with DKIM. I use postsrsd in order for the SPF record to pass for the forwarded emails. However,…
user2370460
  • 213
  • 1
  • 3
  • 7
1
2
3
40 41