Questions tagged [dkim]

DomainKeys Identified Mail is a scheme for signing and verifying email messages to confirm that that the source hasn't been forged, and is typically implemented by MTAs. The source MTA adds a header to the message body containing a signature, and the destination MTA verifies this signature against a key retrieved from DNS.

DomainKeys Identified Mail (DKIM) is an email authentication method designed to detect forged sender addresses in emails (email spoofing), a technique often used in phishing and email spam.

DKIM allows the receiver to check that an email claimed to have come from a specific domain was indeed authorized by the owner of that domain.[1] It achieves this by affixing a digital signature, linked to a domain name, to each outgoing email message. The recipient system can verify this by looking up the sender's public key published in the DNS. A valid signature also guarantees that some parts of the email (possibly including attachments) have not been modified since the signature was affixed.[2] Usually, DKIM signatures are not visible to end-users, and are affixed or verified by the infrastructure rather than the message's authors and recipients.

The first version of DKIM synthesized and enhanced Yahoo!'s DomanKeys and Cisco's Identified Internet Mail specifications. It was the result of a year-long collaboration among numerous industry players, during 2005, to develop an open-standard e-mail authentication specification. Participants included Alt-N Technologies, AOL, Brandenburg InternetWorking, Cisco, EarthLink, IBM, Microsoft, PGP Corporation, Sendmail, StrongMail Systems, Tumbleweed, VeriSign and Yahoo!. The team produced the initial specification and several implementations. It then submitted the work to the IETF for further enhancement and formal standardization.

603 questions
0
votes
1 answer

DKIM Record Not Working

I was setup SPF, DKIM and DMARC Record for my mail server, SPF and DMARC Record are working normally now, But i got a problem for my DKIM Record, When i do: dig default._domainkey.example.com txt The DKIM Record is published, i got a return from dig…
0
votes
0 answers

DKIM validation fails only on Outlook

I'm configuring OpenDKIM to sign miltiple domains with the same key on Pstfix. I followed this tutorial with s=mail and d=example.com. SigningTable: * mail._domainkey.example.com KeyTable: mail._domainkey.example.com …
Demba
  • 11
  • 2
0
votes
2 answers

Postfix can't receive external mails since TLS has been set up

I have a postfix mail server with which I am able to : send mails (to google for example) with the commande : "echo foo | mail -s 'bar' mail@gmail.com" send mails with php mail() send and receive internal mails from and to 'root' or 'myusername'.…
0
votes
1 answer

Failing DKIM when sending postfix email

I set up a postfix/dovecot server. My ISP blocks outbound port 25, so I use an SMTP relay (mailjet). When I send an email to gmail, it ends up in the "promotions" category which is effectively the spam folder. How can I fix this? Closer inspection…
Stewart
  • 341
  • 1
  • 3
  • 12
0
votes
1 answer

Is everything OK based on this DMARC report?

Do I understand it correct that everything is OK and I have both SPF and DKIM configured correctly based on this report from Google? google.com
IvanD
  • 103
  • 2
0
votes
1 answer

DKIM - key pair generation recommendations

I wonder if it is okay to generate a key pair (.key and .cert files) for DKIM like this: openssl req -newkey rsa:2048 -sha256 -x509 -nodes -days 3650 -keyout dkim-rsa.key -out dkim-rsa.cert By reading RFC 6376 I can see that standards only demand…
71GA
  • 363
  • 1
  • 3
  • 10
0
votes
1 answer

Would adding CNAME records in DNS server for setting up DKIM cause email server issues?

I want to add two CNAME records to make my Microsoft exchange be DKIM compliant according to Microsoft.com’s instructions. Is there any possibility adding the two CNAME records would cause disruptions to people sending emails in exchange? CNAME…
BornPerson
  • 103
  • 4
0
votes
1 answer

System to prove content of a DNS record/DKIM key at a certain time?

I'm trying to build a way to prove that an e-mail was indeed sent from a specific domain. Is there a service that allows me to demonstrate what value a TXT record had at a certain time, e.g. by providing a signed DNS response, or an archive of past…
Jan Schejbal
  • 171
  • 3
0
votes
1 answer

DKIM and subdomains

We use a sub domain "mail.domain.com" for sending marketing emails from Salesforce Marketing Cloud, the reason it was set up this way is to keep the reputation of this domain separate from our normal domain "domain.com". All of the links within the…
0
votes
1 answer

DKIM and multiple Email protection Gateways

Just wondering if anyone has ever setup DKIM with multiple email protection gateways We are running with 365 and a couple of email protection gateways in front Do you need to add the public key to each gateway? or just enable DKIM on 365 and it will…
Xebus
  • 1
0
votes
1 answer

How to set Public Key DKIM in Postfix

I need to set up my public key in the postfix server, I already generated the keys in https://dkimcore.org/tools/, and added the TXT records in my DNS provider. But I have no idea how to set it in my postfix server, I'm checking for some tutorials…
0
votes
2 answers

Email protected with SPF but received valid signature from other IP anyway

I've received an email in spam from info@mydomain.com to info@mydomain.com, but the "sent by" came from rec15.appleandrdoidmail.mx. info@mydomain.com is an alias. Weird thing is that it says is signed by mydomain.com! I've been looking at the email…
Miquel
  • 103
  • 5
0
votes
1 answer

DKIM aligned but not authenticated on On-Premises Exchange 2019

I have an On-Premises Exchange 2019 server with Hybrid Deployment with Office365 configured. Everything is working as expected, but DKIM aligned messages are arriving as unauthenticated. I can confirm that the sender have properly authenticated…
Vinícius Ferrão
  • 5,520
  • 11
  • 55
  • 95
0
votes
0 answers

Issue with opendkim key not valid in dns check

I am checking the dkim key generated by opendkim and I keep getting an error of key not valid. Here is the output of mail.txt key file: I replaced my domain with example.com in this scenario. mail._domainkey IN TXT ( "v=DKIM1; h=sha256;…
Steve K
  • 125
  • 1
  • 6
0
votes
1 answer

SPF and DKIM for one domain on two servers

I followed this guide to setup SPF and DKIM for emails to be sent from a server for a domain. That server is the location of the actual email server for the domain. I now want to setup another server to be able to send emails from the domain via…
Kohjah Breese
  • 171
  • 2
  • 13