Questions tagged [dkim]

DomainKeys Identified Mail is a scheme for signing and verifying email messages to confirm that that the source hasn't been forged, and is typically implemented by MTAs. The source MTA adds a header to the message body containing a signature, and the destination MTA verifies this signature against a key retrieved from DNS.

DomainKeys Identified Mail (DKIM) is an email authentication method designed to detect forged sender addresses in emails (email spoofing), a technique often used in phishing and email spam.

DKIM allows the receiver to check that an email claimed to have come from a specific domain was indeed authorized by the owner of that domain.[1] It achieves this by affixing a digital signature, linked to a domain name, to each outgoing email message. The recipient system can verify this by looking up the sender's public key published in the DNS. A valid signature also guarantees that some parts of the email (possibly including attachments) have not been modified since the signature was affixed.[2] Usually, DKIM signatures are not visible to end-users, and are affixed or verified by the infrastructure rather than the message's authors and recipients.

The first version of DKIM synthesized and enhanced Yahoo!'s DomanKeys and Cisco's Identified Internet Mail specifications. It was the result of a year-long collaboration among numerous industry players, during 2005, to develop an open-standard e-mail authentication specification. Participants included Alt-N Technologies, AOL, Brandenburg InternetWorking, Cisco, EarthLink, IBM, Microsoft, PGP Corporation, Sendmail, StrongMail Systems, Tumbleweed, VeriSign and Yahoo!. The team produced the initial specification and several implementations. It then submitted the work to the IETF for further enhancement and formal standardization.

603 questions
0
votes
1 answer

How can it be possible dkim fails whereas spf pass

I have set up a postfix which sends emails. I have configure spf, dkim and dmarc (with p=none). I have checked with mail-tester: spf and dkim work fine. I have set up a dmarc rua in order to receive dmarc reports. I have seen something strange in…
Bob5421
  • 319
  • 3
  • 8
  • 16
0
votes
0 answers

Is the a Postfix milter supporting dkim with IDN and UTF8

I use postfix mailserver with enabled SMTPUTF8 and some IDNs, before I used IDNs I used OpenDKIM, but OpenDKIM crashes if I use the IDN in utf8 form. Then I tried pyopendkim. Then I tried dkimpy-milter, but it just does not sign UTF8 mails. Is there…
user949712
0
votes
1 answer

Does Postfix add the DKIM header before or after a message is queued?

The Postfix configuration has been changed to add a DKIM header when sending a mail. But Postfix is currently in the stop status, and mailq shows that new mails have been queuing in the meantime. Will postfix start make Postfix add the DKIM header…
Déjà vu
  • 5,546
  • 9
  • 36
  • 55
0
votes
1 answer

How do I add individual mail-sending websites to my SPF record?

My company, which sends @example.co email from Google Workspace, HubSpot, and Salesforce, has the following SPF record in DNS: v=spf1 include:_spf.google.com include:_spf.salesforce.com include:xxxxxxxx.xxxxx.hubspotemail.net ~all We also have…
ST7686
  • 1
0
votes
1 answer

Create a DKIM key to provide to a 3rd party so we can send as them?

We use o365/Exchange Online. All our SPF and DKIM configs are good for our domain (including 3rd party senders). Say we have a partner who has domain XYZ123.com (with their own mail servers) and they want us to be able to send as them (from our…
techie007
  • 1,894
  • 17
  • 25
0
votes
0 answers

Authorized domain in exchange 2010 would not send email to internet but internally to main domain

An authorized domain authorized-domain.tld in exchange 2010 with main domain main-domain.tld would not send email to internet but internally to main domain. Reproduced / describde scenario: User opens outlook client 2010 and binds the authorized…
Manifest Man
  • 113
  • 1
  • 6
0
votes
1 answer

SPF/DKIM setup for a registrar's email forward

I have a number of domains with a registrar with straight forward forwards to another email address. The system has worked flawlessly for a lot of years over a lot of domains but recently I created a new forward which failed on testing. The error…
0
votes
2 answers

Doubts about DKIM verification (RFC6376)

Good morning, https://www.rfc-editor.org/rfc/rfc6376#section-5 reads: "Survivability of signatures after transit is not guaranteed, and signatures can fail to verify through no fault of the Signer. Therefore, a Verifier SHOULD NOT treat a message…
Tom Johnson
  • 107
  • 3
0
votes
0 answers

Incoming DKIM verfication check working but not rejecting

I have SPF, DMARC and DKIM configured for my mail server (postfix) on a CentOS 7 OS. Outgoing mail is getting signed as normal. All email check sites says my stuff are secured and working great but there is a site I use that purposely sends various…
iraqiboy90
  • 21
  • 4
0
votes
1 answer

Emails are going to spam

Hey guys, I am currently running exchange 2010, I have implemented SPF record, and tried to implement dkim/domain keys using domain sink, but it doesn't seem to work. The problem I am having is that all my emails go to spam, whenever I email some…
Sam
0
votes
2 answers

DKIM on subdomain hosted by domain.com, and auto-generated DKIM key

I've read a few different threads on here and have tried them out, but they don't seem to be working for me, so I'm hoping one of you awesome people can help me out. Forgive me, but this will be a little long. I'm working with a non-profit who has…
0
votes
1 answer

DMARC appears to fail, multiple DKIM signatures with one matching the from address

I am using a free outlook account. In the outlook account management portal I have added an alias for my custom domain (alias@mydomain.website). With this I am able to send mails from this alias, which appear in the receivers mailbox as "outlook…
0
votes
0 answers

DMARC, DKIM, or SPF? Emails going into quarantine

I have never had to deal with DKIM, DMARC, or SPF records before; however, our SPF record is full (10, Cloudflare) and I have a vendor whose emails aren’t making it to our mailboxes. I made exceptions in our spam filter for the emails, and have…
Cody
  • 1
0
votes
1 answer

DMARC report with passing O365 DKIM signature being sent by Google server

The dmarc report values are as follows: dkim_domain : mydomain.onmicrosoft.com dkim_result : pass selector : selector1-mydomain-onmicrosoft-com header_from : mydomain spf_domain : mydomain spf_result : fail source_ip : 209.85.219.70 (this is a…
Adam Winter
  • 129
  • 1
  • 6
0
votes
1 answer

Send each email from a different subdomain?

There are clearly benefits of using a subdomain for sending email to protection domain reputation, but is this always true? What about the extreme case, where a spam domain sends every email from a distinct subdomain?
rosstex
  • 133
  • 1
  • 5