Questions tagged [dkim]

DomainKeys Identified Mail is a scheme for signing and verifying email messages to confirm that that the source hasn't been forged, and is typically implemented by MTAs. The source MTA adds a header to the message body containing a signature, and the destination MTA verifies this signature against a key retrieved from DNS.

DomainKeys Identified Mail (DKIM) is an email authentication method designed to detect forged sender addresses in emails (email spoofing), a technique often used in phishing and email spam.

DKIM allows the receiver to check that an email claimed to have come from a specific domain was indeed authorized by the owner of that domain.[1] It achieves this by affixing a digital signature, linked to a domain name, to each outgoing email message. The recipient system can verify this by looking up the sender's public key published in the DNS. A valid signature also guarantees that some parts of the email (possibly including attachments) have not been modified since the signature was affixed.[2] Usually, DKIM signatures are not visible to end-users, and are affixed or verified by the infrastructure rather than the message's authors and recipients.

The first version of DKIM synthesized and enhanced Yahoo!'s DomanKeys and Cisco's Identified Internet Mail specifications. It was the result of a year-long collaboration among numerous industry players, during 2005, to develop an open-standard e-mail authentication specification. Participants included Alt-N Technologies, AOL, Brandenburg InternetWorking, Cisco, EarthLink, IBM, Microsoft, PGP Corporation, Sendmail, StrongMail Systems, Tumbleweed, VeriSign and Yahoo!. The team produced the initial specification and several implementations. It then submitted the work to the IETF for further enhancement and formal standardization.

603 questions
0
votes
0 answers

DKIM and sending email on behalf of many domains - explain it to me like I'm a dummy

We run a server that provides a service for a few hundred customers, and there's a feature that allows them to generate some automated emails which go out to various colleagues and external partners. Some of our clients want to use their company…
popkinson
  • 1
  • 1
0
votes
1 answer

DKIM E-Mail verification - prevent receivers from accepting unsigned emails?

I have set up SPF, DKIM and DMARC in my domain (to the best that I can figure out), but I still can send spoofed emails - without a DKIM signature - and they are accepted (at least when I test with GMail - I assume they will be the most strict about…
Guss
  • 2,670
  • 5
  • 34
  • 59
0
votes
0 answers

How to correctly configure OpenDKIM with Postfix on Debian 11?

The desired settings are to create a multi domain mail server. This is my main domain example.com and this is my subdomain: mail.example.com Taking the rDNS as the following verifications: hostname -f nano /etc/mailname nano /etc/hostname As a…
J. Mick
  • 101
0
votes
2 answers

Should e-mails signed with another domain's DKIM key be treated as spam?

Every now and then I browse my spam folder (for science!). Recently (after adding DKIM Verifier plugin to my MUA) I noticed that some e-mails have valid DKIM signature, but the Verifier points out that sender domain and signing domain are different.…
madman_xxx
  • 198
  • 6
0
votes
1 answer

Email goes to spam even with valid SPF, DKIM and DMARC records, dynamic rDNS on AWS instance

I have an instance on AWS and fighting with sending emails through cPanel. All records are OK (checked on MX toolbox): SPF, DKIM, DMARC at the cPanel level and the WHM level (hostname). Even rDNS is OK. Server IP is not flagged or blacklisted…
Adrian P.
  • 101
  • 2
0
votes
0 answers

SendMail Bounce Back Missing Send To Address in Transcript

SendMail bounce back response is showing a blank To address. How can I correct this so the bounce back includes the To address? This began occurring after installing opendkim on the server and before DKIM was enabled. Sendmail version did not…
Dorothy
  • 179
  • 7
0
votes
1 answer

Mails from my domain to gmail always in spam

I have a problem, all mails from my domain (lcs-proprete.fr) to GMAIL users only go to their spam folder. SPF is ok, DKIM is okay and DMARC is configured as p=none I disable dkim to be sure that the problem does not come from that but don't change…
0
votes
1 answer

dkim key error with bind9 dns

I am having an issue while configuring dkim with postfix on ubuntu 20.04, as i get the following error: opendkim-testkey -d example.com -s khloud -vvv opendkim-testkey: using default configfile /etc/opendkim.conf opendkim-testkey: key loaded from…
0
votes
1 answer

Network Solutions DNS not always returning DKIM and SPF records

If there is a more appropriate place to ask this or it is a duplicate, please tell me. I have a client who hosts their domains with Network Solutions. Some of their emails were bouncing due to stricter authorization requirements enforced on certain…
jdmayfield
  • 281
  • 3
  • 13
0
votes
0 answers

DKIM: validation error: error:RSA_padding_check_PKCS1_type_1:invalid padding

We receive a lot of spam on our servers from 3rd party servers and often this spam includes the email header such as: DKIM: validation error: error:0407008A:rsa routines:RSA_padding_check_PKCS1_type_1:invalid padding This can be caused by many…
Martin
  • 209
  • 1
  • 2
  • 13
0
votes
2 answers

Why did this incoming email get through Office 365 spam filters with a DKIM fail? What policy do I need to "tune"?

We use Office 365 mail, I got this spam email this morning so I checked the header to see if there was anything I could do. Here is the header with our receipt domain removed Received: from DB6PR01MB3829.eurprd01.prod.exchangelabs.com …
AngryCarrotTop
  • 288
  • 4
  • 11
0
votes
0 answers

DKIM_INVALID in Spamassassin only for emails sent from other emails in the same server

I have postfix/dovecot running with spamassassin on Centos. PROBLEM: The VPS acts as a mail server Spamassassin edits the email subject and adds [SPAM} Ms. Outlook on Windows moves those emails to the Junk folder The above happens ONLY if an email…
Pikk
  • 339
  • 1
  • 6
  • 19
0
votes
1 answer

OpenDKIM - can't load key

Hi I am trying to setup OpenDKIM, but it keeps complaining it cannot access the keyfile. I have double checked permissions and ownership, which is set to user opendkim & group opendkim with rw access. I have disabled selinux to rule out an selinux…
arno77
  • 13
  • 3
0
votes
0 answers

postfix to gmail silent delivery failure

With the impending turndown of free hosted Google workspace accounts, I'm trying to install my own mail server using postfix/dovecot/opendkim. Mostly, it's working and for many of the services I've tried delivery is flowing. However, when I send an…
0
votes
0 answers

AWS SES subdomain email

Can I add CNAME and MX records to a subdomain hosted outside Amazon to work with AWS SES? I have bill@example.com and jill@example.com. I would like to leave bill as is while transferring jill over to use with AWS services. Can this be done? Would…