Questions tagged [dkim]

DomainKeys Identified Mail is a scheme for signing and verifying email messages to confirm that that the source hasn't been forged, and is typically implemented by MTAs. The source MTA adds a header to the message body containing a signature, and the destination MTA verifies this signature against a key retrieved from DNS.

DomainKeys Identified Mail (DKIM) is an email authentication method designed to detect forged sender addresses in emails (email spoofing), a technique often used in phishing and email spam.

DKIM allows the receiver to check that an email claimed to have come from a specific domain was indeed authorized by the owner of that domain.[1] It achieves this by affixing a digital signature, linked to a domain name, to each outgoing email message. The recipient system can verify this by looking up the sender's public key published in the DNS. A valid signature also guarantees that some parts of the email (possibly including attachments) have not been modified since the signature was affixed.[2] Usually, DKIM signatures are not visible to end-users, and are affixed or verified by the infrastructure rather than the message's authors and recipients.

The first version of DKIM synthesized and enhanced Yahoo!'s DomanKeys and Cisco's Identified Internet Mail specifications. It was the result of a year-long collaboration among numerous industry players, during 2005, to develop an open-standard e-mail authentication specification. Participants included Alt-N Technologies, AOL, Brandenburg InternetWorking, Cisco, EarthLink, IBM, Microsoft, PGP Corporation, Sendmail, StrongMail Systems, Tumbleweed, VeriSign and Yahoo!. The team produced the initial specification and several implementations. It then submitted the work to the IETF for further enhancement and formal standardization.

603 questions
6
votes
1 answer

Mail from Teams forwarded to Gmail marked as spam due to DMARC failure

When I write a chat message in Microsoft Teams the receiver gets an e-mail notification on her Office 365 account (receiver@htlvb.at) when she is offline in Teams. The receiver set it up so that all her mails are forwarded to her personal Gmail…
Johannes Egger
  • 173
  • 1
  • 6
6
votes
1 answer

No DKIM headers in sent mails from postfix

I have two postfix, one for receiving mails and the other for sending mails, and I am having trouble signing dkim on my outgoing mails. I followed this tutorial. Logs also is not helping me point to the main problem. OpenDKIM is running fine: ●…
user13539846
  • 161
  • 3
5
votes
3 answers

Is it possible to find a list of all DKIM keys for a domain?

a DKIM-record is identified by its selector, which might be default, dkim or something else alltogether (and there might be multiple). When making sure that an e-mail's content is valid, the DKIM selector that is mentioned in the e-mail can be used…
Qqwy
  • 149
  • 1
  • 1
  • 5
5
votes
1 answer

NOT receiving DMARC reports from AOL / HOTMAIL / MSN / OUTLOOK / LIVE

My DMARC DNS record looks like this: (domain name is redacted) _dmarc.domain.com TXT "v=DMARC1; p=none; sp=none; rua=mailto:dmarc@domain.com; ruf=mailto:dmarc@domain.com; rf=afrf; pct=100; ri=86400" Now, I receive aggregate DMARC and forensic…
whallz
  • 103
  • 6
5
votes
1 answer

DKIM: 'not authenticated' but 'verification successful'

A question if this is normal DKIM behaviour. When sending an email from mydomain it adds it with a signature, and it looks good. But when receiving an email from outside, say outlook.com, i get below: Is "not authenticated" normal behaviour? It does…
user431710
  • 71
  • 1
  • 5
5
votes
2 answers

how to configuration dkim on exchange email server

Mails sent from our internal email server to public servers such as Gmail, Yahoo and all other external organizations are delivering to spam. We currently use exchange server, in order to tackle above mentioned problem we would like to configure…
enkhtuvshin
  • 51
  • 1
  • 1
  • 2
5
votes
3 answers

Google Apps email DKIM won't authenticate

We're trying to set up DKIM authentication on our Google Apps/G Suite for Business domain to reduce the number of our emails which are ending up in people's spam folders. We have generated the DKIM key and set it up in Google Cloud DNS and have…
Bdoserror
  • 184
  • 1
  • 13
5
votes
2 answers

Why do I need to escape ; with \ in a DNS DKIM record?

I'm setting up Email Authentication on our domain to allow authentication with our Email Service Provider. My understanding is that the DNS record needs to have any ; escaped, e.g., \; I just want to make sure that ALL ; should be escaped. To that…
Clay Nichols
  • 1,431
  • 6
  • 25
  • 30
5
votes
3 answers

Is there anything bad about DKIM-signing mail without the key in DNS?

At a site that I manage, we send out emails for many customer domains. Some of them have our DKIM key in DNS, some don't. From what I can tell: Signature verification failure does not force rejection of the message. But is that actually the case?…
MikeyB
  • 39,291
  • 10
  • 105
  • 189
5
votes
1 answer

When creating DomainKeys does it matter if I use o=~ or o=-?

I used this utility to create my DKIM key (1024 bit size), since Gmail has been blocking us (we had an old joomla install exploited, was around before me). And I got this back: Your Selector Record: default._domainkey.example.com IN…
hardbizkit
  • 51
  • 1
  • 2
5
votes
1 answer

DKIM body hash fail

We're sending out e-mails with EXIM 4.71 from a PHP application. DKIM is enabled and is working properly, unless when sending a specific type of mails, which results in dkim=neutral (body hash did not verify). Received-SPF: pass (google.com: domain…
Oscar
  • 181
  • 1
  • 9
5
votes
3 answers

PTR OK, SPF, DKIM passed but email messages are marked as Spam by Google?

# host 1.2.3.4 4.3.2.1.in-addr.arpa domain name pointer mail.domain.vn. # dig +short txt domain.vn "v=spf1 a mx ptr -all" # dig +short txt mail.domain.vn "v=spf1 a -all" Here's an email header that is marked as Spam: Delivered-To:…
quanta
  • 51,413
  • 19
  • 159
  • 217
5
votes
1 answer

Why doesn't dkim sign the letter?

I have configured DKIM: Dec 27 11:10:03 mailer opendkim[378]: OpenDKIM Filter v2.11.0 starting (args: -x /etc/opendkim.conf) Dec 27 11:10:10 mailer postfix/postfix-script[551]: warning: symlink leaves directory: /etc/postfix/./makedefs.out Dec 27…
Oleksandr
  • 161
  • 1
  • 7
5
votes
2 answers

Why does spf fail in DMARC report from Google?

I recently received a DMARC report from Google alerting me of a few SPF failures with mail originating from IP addresses belonging to Amazon SES. A sample record is as follows (I have replaced our domain with example.com.):
5
votes
1 answer

1024 or 2048 bit keys for DKIM?

Referencing this: https://crypto.stackexchange.com/questions/72297/recommended-key-size-for-dkim What I get from this is (at the time) DNS providers (usually) allow for up to 1024 bit keys but not 2048 bit. Now, my provider does let me use 2048 and…
Tyler Montney
  • 201
  • 2
  • 8