Questions tagged [dkim]

DomainKeys Identified Mail is a scheme for signing and verifying email messages to confirm that that the source hasn't been forged, and is typically implemented by MTAs. The source MTA adds a header to the message body containing a signature, and the destination MTA verifies this signature against a key retrieved from DNS.

DomainKeys Identified Mail (DKIM) is an email authentication method designed to detect forged sender addresses in emails (email spoofing), a technique often used in phishing and email spam.

DKIM allows the receiver to check that an email claimed to have come from a specific domain was indeed authorized by the owner of that domain.[1] It achieves this by affixing a digital signature, linked to a domain name, to each outgoing email message. The recipient system can verify this by looking up the sender's public key published in the DNS. A valid signature also guarantees that some parts of the email (possibly including attachments) have not been modified since the signature was affixed.[2] Usually, DKIM signatures are not visible to end-users, and are affixed or verified by the infrastructure rather than the message's authors and recipients.

The first version of DKIM synthesized and enhanced Yahoo!'s DomanKeys and Cisco's Identified Internet Mail specifications. It was the result of a year-long collaboration among numerous industry players, during 2005, to develop an open-standard e-mail authentication specification. Participants included Alt-N Technologies, AOL, Brandenburg InternetWorking, Cisco, EarthLink, IBM, Microsoft, PGP Corporation, Sendmail, StrongMail Systems, Tumbleweed, VeriSign and Yahoo!. The team produced the initial specification and several implementations. It then submitted the work to the IETF for further enhancement and formal standardization.

603 questions
4
votes
1 answer

DMARC is blocking email that seems like it should be allowed

This is the DMARC record we have set v=DMARC1; p=reject; rua=mailto:[redacted]@coinbase.com; adkim=r; aspf=s So we are rejecting any not match with SPF strictly, and DKIM is relaxed. Here is the SPF record: v=spf1 mx ptr include:_spf.google.com…
Brian Armstrong
  • 1,617
  • 3
  • 19
  • 22
4
votes
1 answer

How to prevent emails from my domain through mailing lists to be rejected due to DMARC

I operate my own mail server at speedofsoundgaming.com and mwtd.net. I recently added a DMARC record to my domain to help prevent spam, and once seeing that things seemed to be working, upped the level to quarantine from none. However, I had not…
4
votes
2 answers

Postfix with DKIM on Ubuntu

I want to improve deliverability for my outgoing emails with DKIM. I've gotten dkim-filter installed for postfix, using this tutorial https://help.ubuntu.com/community/Postfix/DKIM It seems to be working, my /var/log/mail.log shows it starting: Aug…
Brian Armstrong
  • 1,617
  • 3
  • 19
  • 22
4
votes
2 answers

How to avoid messages rejection because of DMARC when sent through Gmail alias?

Many people add ' another email address as alias ' for their Gmail accounts - talking here about public Gmail not Google Apps - and they may use Gmail server not their domain servers as SMTP with the ' Treat as an 'alias' setting '. While DMARC not…
hsobhy
  • 181
  • 1
  • 2
  • 10
4
votes
1 answer

Does DKIM works with subdomains?

ISP's recommend you segment your marketing and transactional emails by using different IPs. I want to start using DKIM, but since DKIM is a domain based reputation system I wonder if signing with the same company.com domain will impact the…
4
votes
1 answer

What problems can an ADSP record in DNS cause for mailflow?

ADSP is an entry in DNS that works allows a domain owner to assert that all email must be signed with DKIM. (similar to the -all and ~all in SPF/SenderID). Messages that fail ADSP policy may be rejected. Apparently DKIM has a ton of issues with…
makerofthings7
  • 8,911
  • 34
  • 121
  • 197
4
votes
1 answer

Yahoo Domain Keys setup, getting dkim=permerror (no key)

I'm working on getting DKIM installed on my outgoing mail server, to help my email deliverability to my Yahoo clients (all legit emails, etc, no spamming). I've got DKIM-Signature: and DomainKey-Signature: headers being generated, but a test mailer…
Ian
  • 1,498
  • 4
  • 26
  • 32
4
votes
2 answers

DMARC fail, but DKIM and SPF are passing

I am using AWS SES (in sandbox mode) to send an email to a GMail address. Unfortunately it gets flagged as spam. Google is nice enough to tell me in the message details that it is a DMARC failure I read the official documentation :…
YannP
  • 163
  • 1
  • 5
3
votes
2 answers

SPAM Domain Spoofing through SES

A spammer seems to be running spam through SES and spoofing our domain. We are using SPF and DKIM so I’m not sure what is going on. This is our SPF record: v=spf1 a mx include:amazonses.com include:_spf.google.com include:secureserver.net ~all I…
3
votes
1 answer

Postfix does not pass mails to Amavis, when received from Z-push

Im kind of staring myself blind in how get ActiveSync to work correctly with my mailserver, so maybe anybody here have an idea? The deal is mailserver is hosting four domains and I want that all sent mails have DKIM signature. I have gotten it to…
3
votes
1 answer

DKIM "default" selector

I often see DKIM configuration guides using default as the selector. Is this a special selector or it is just a convention to use this if you only have one mail server? In other words, if I use the selector default._domainkeys.example.com, will this…
Charlie Patton
  • 133
  • 1
  • 5
3
votes
2 answers

OpenDKIM / Postfix sign console-sent mail, but not from a mail client / SMTP

I have Postfix running on a Debian 9 machine, and installed opendkim (both from the Debian repositories). The milter socket/connection is inet:localhost:8892, and the iptables firewall allows that connection (a telnet localhost 8892…
Cal-linux
  • 175
  • 1
  • 2
  • 8
3
votes
1 answer

Postfix setup with different domain name, reverse lookup and SPF

I would like to set up Postfix properly to serve multiple virtual domains while complying to all standards and being able to enable security measures like SPF. The server has the hostname server.domain.tld. Postfix has mydomain set to…
3
votes
1 answer

Exim4 config - setting DKIM_DOMAIN

I've set up DKIM wit exim4 on my debian server. Everything is working correctly with one fixed domain, e.g. the following works perfectly fine. DKIM_DOMAIN = example.com Now I'm trying to change this to work with multi-domains. So I've changed…
Aleks G
  • 936
  • 2
  • 8
  • 18
3
votes
0 answers

Accept or not to accept DKIM signed emails on my smtp server which source DNS don't has signature

In the outgoing emails we use in our domains SPF + DKIM without any problem. But with the inbound emails some time ago we're receiving emails from some of our customers/suppliers signed with DKIM, but they don't have set any public signature on…
NetVicious
  • 462
  • 5
  • 17