<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<title type="html"><![CDATA[iRedMail — DKIM Mail signing]]></title>
	<link rel="self" href="http://www.iredmail.org/forum/feed-atom-topic412.xml" />
	<updated>2009-11-14T13:45:03Z</updated>
	<generator>PunBB</generator>
	<id>http://www.iredmail.org/forum/topic412-dkim-mail-signing.html</id>
		<entry>
			<title type="html"><![CDATA[Re: DKIM Mail signing]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/post1815.html#p1815" />
			<content type="html"><![CDATA[<p>when sending through horde the result will be:</p><p>==========================================================<br />Summary of Results<br />==========================================================<br />SPF check:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; pass<br />DomainKeys check:&nbsp; &nbsp;neutral<br />DKIM check:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;neutral<br />Sender-ID check:&nbsp; &nbsp; pass<br />SpamAssassin check: ham</p><p>==========================================================<br />Details:<br />==========================================================</p><p>HELO hostname:&nbsp; mail.bigmichi1.de<br />Source IP:&nbsp; &nbsp; &nbsp; 188.40.84.226<br />mail-from:&nbsp; &nbsp; &nbsp; michael@bigmichi1.de</p><p>----------------------------------------------------------<br />SPF check details:<br />----------------------------------------------------------<br />Result:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;pass <br />ID(s) verified: smtp.mail=michael@bigmichi1.de<br />DNS record(s):<br />&nbsp; &nbsp; bigmichi1.de. 86400 IN TXT &quot;v=spf1 mx mx:mail.bigmichi1.de -all&quot;<br />&nbsp; &nbsp; bigmichi1.de. 86400 IN MX 10 mail.bigmichi1.de.<br />&nbsp; &nbsp; srv03.bigmichi1.de. 86400 IN A 188.40.84.226</p><p>----------------------------------------------------------<br />DomainKeys check details:<br />----------------------------------------------------------<br />Result:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;neutral (message not signed)<br />ID(s) verified: header.From=michael@bigmichi1.de<br />DNS record(s):</p><p>----------------------------------------------------------<br />DKIM check details:<br />----------------------------------------------------------<br />Result:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;neutral (message not signed)<br />ID(s) verified: </p><p>NOTE: DKIM checking has been performed based on the latest DKIM specs<br />(RFC 4871 or draft-ietf-dkim-base-10) and verification may fail for<br />older versions.&nbsp; If you are using Port25&#039;s PowerMTA, you need to use<br />version 3.2r11 or later to get a compatible version of DKIM.</p><p>----------------------------------------------------------<br />Sender-ID check details:<br />----------------------------------------------------------<br />Result:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;pass <br />ID(s) verified: header.From=michael@bigmichi1.de<br />DNS record(s):<br />&nbsp; &nbsp; bigmichi1.de. 86400 IN TXT &quot;v=spf1 mx mx:mail.bigmichi1.de -all&quot;<br />&nbsp; &nbsp; bigmichi1.de. 86400 IN MX 10 mail.bigmichi1.de.<br />&nbsp; &nbsp; srv03.bigmichi1.de. 86400 IN A 188.40.84.226</p><p>----------------------------------------------------------<br />SpamAssassin check details:<br />----------------------------------------------------------<br />SpamAssassin v3.2.5 (2008-06-10)</p><p>Result:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;ham&nbsp; (0.9 points, 5.0 required)</p><p> pts rule name&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; description<br />---- ---------------------- --------------------------------------------------<br />-0.0 SPF_PASS&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;SPF: sender matches SPF record<br /> 0.0 MIME_HTML_MOSTLY&nbsp; &nbsp; &nbsp; &nbsp;BODY: Multipart message mostly text/html MIME<br /> 0.0 HTML_MESSAGE&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;BODY: HTML included in message<br /> 2.2 TVD_SPACE_RATIO&nbsp; &nbsp; &nbsp; &nbsp; BODY: TVD_SPACE_RATIO<br />-0.7 BAYES_20&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;BODY: Bayesian spam probability is 5 to 20%<br />&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; [score: 0.1824]<br />-0.6 AWL&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; AWL: From: address is in the auto white-list</p><br /><p>when sending through thunderbird from my home machine the result is:</p><p>==========================================================<br />Summary of Results<br />==========================================================<br />SPF check:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; pass<br />DomainKeys check:&nbsp; &nbsp;neutral<br />DKIM check:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;pass<br />Sender-ID check:&nbsp; &nbsp; pass<br />SpamAssassin check: ham</p><p>==========================================================<br />Details:<br />==========================================================</p><p>HELO hostname:&nbsp; mail.bigmichi1.de<br />Source IP:&nbsp; &nbsp; &nbsp; 188.40.84.226<br />mail-from:&nbsp; &nbsp; &nbsp; michael@bigmichi1.de</p><p>----------------------------------------------------------<br />SPF check details:<br />----------------------------------------------------------<br />Result:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;pass <br />ID(s) verified: smtp.mail=michael@bigmichi1.de<br />DNS record(s):<br />&nbsp; &nbsp; bigmichi1.de. 86400 IN TXT &quot;v=spf1 mx mx:mail.bigmichi1.de -all&quot;<br />&nbsp; &nbsp; bigmichi1.de. 86400 IN MX 10 mail.bigmichi1.de.<br />&nbsp; &nbsp; srv03.bigmichi1.de. 86400 IN A 188.40.84.226</p><p>----------------------------------------------------------<br />DomainKeys check details:<br />----------------------------------------------------------<br />Result:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;neutral (message not signed)<br />ID(s) verified: header.From=michael@bigmichi1.de<br />DNS record(s):</p><p>----------------------------------------------------------<br />DKIM check details:<br />----------------------------------------------------------<br />Result:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;pass (matches From: michael@bigmichi1.de)<br />ID(s) verified: header.d=bigmichi1.de<br />Canonicalized Headers:<br />&nbsp; &nbsp; content-transfer-encoding:7bit&#039;0D&#039;&#039;0A&#039;<br />&nbsp; &nbsp; content-type:text/plain;&#039;20&#039;charset=ISO-8859-15;&#039;20&#039;format=flowed&#039;0D&#039;&#039;0A&#039;<br />&nbsp; &nbsp; subject:Check&#039;0D&#039;&#039;0A&#039;<br />&nbsp; &nbsp; to:check-auth@verifier.port25.com&#039;0D&#039;&#039;0A&#039;<br />&nbsp; &nbsp; mime-version:1.0&#039;0D&#039;&#039;0A&#039;<br />&nbsp; &nbsp; user-agent:Thunderbird&#039;20&#039;2.0.0.23&#039;20&#039;(Windows/20090812)&#039;0D&#039;&#039;0A&#039;<br />&nbsp; &nbsp; from:Michael&#039;20&#039;Cramer&#039;20&#039;&lt;michael@bigmichi1.de&gt;&#039;0D&#039;&#039;0A&#039;<br />&nbsp; &nbsp; date:Sat,&#039;20&#039;14&#039;20&#039;Nov&#039;20&#039;2009&#039;20&#039;13:33:57&#039;20&#039;+0100&#039;0D&#039;&#039;0A&#039;<br />&nbsp; &nbsp; message-id:&lt;4AFEA3B5.2030507@bigmichi1.de&gt;&#039;0D&#039;&#039;0A&#039;<br />&nbsp; &nbsp; x-virus-scanned:Debian&#039;20&#039;amavisd-new&#039;20&#039;at&#039;20&#039;mail.bigmichi1.de&#039;0D&#039;&#039;0A&#039;<br />&nbsp; &nbsp; dkim-signature:v=1;&#039;20&#039;a=rsa-sha256;&#039;20&#039;c=relaxed/simple;&#039;20&#039;d=bigmichi1.de;&#039;20&#039;h=&#039;20&#039;content-transfer-encoding:content-type:subject:to:mime-version&#039;20&#039;:user-agent:from:date:message-id:x-virus-scanned;&#039;20&#039;s=dkim;&#039;20&#039;t=&#039;20&#039;1258205711;&#039;20&#039;x=1259069711;&#039;20&#039;bh=frcCV1k9oG9oKj3dpUqdJg1PxRT2RSN/XKd&#039;20&#039;LCPjaYaY=;&#039;20&#039;b=</p><p>Canonicalized Body:<br />&nbsp; &nbsp; &#039;0D&#039;&#039;0A&#039;<br />&nbsp; &nbsp; </p><p>DNS record(s):<br />&nbsp; &nbsp; dkim._domainkey.bigmichi1.de. 3600 IN TXT &quot;v=DKIM1; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDd7Ayf1dZ1ycq2lEO2rH7YJVL1luac4pKSZd1B+JwjXQezZECL26kz4ko3WMLMXnXQSBxLQa2NUeUIhz/BoEBqJXacETzYYKM95Q5gHWA/oec57A/Vf26Mxy8jNRKYF+WSFYuqL7fZUff9frWyF7wlDz0acS+jVVwILQ9vvh7bgwIDAQAB&quot;</p><p>NOTE: DKIM checking has been performed based on the latest DKIM specs<br />(RFC 4871 or draft-ietf-dkim-base-10) and verification may fail for<br />older versions.&nbsp; If you are using Port25&#039;s PowerMTA, you need to use<br />version 3.2r11 or later to get a compatible version of DKIM.</p><p>----------------------------------------------------------<br />Sender-ID check details:<br />----------------------------------------------------------<br />Result:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;pass <br />ID(s) verified: header.From=michael@bigmichi1.de<br />DNS record(s):<br />&nbsp; &nbsp; bigmichi1.de. 86400 IN TXT &quot;v=spf1 mx mx:mail.bigmichi1.de -all&quot;<br />&nbsp; &nbsp; bigmichi1.de. 86400 IN MX 10 mail.bigmichi1.de.<br />&nbsp; &nbsp; srv03.bigmichi1.de. 86400 IN A 188.40.84.226</p><p>----------------------------------------------------------<br />SpamAssassin check details:<br />----------------------------------------------------------<br />SpamAssassin v3.2.5 (2008-06-10)</p><p>Result:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;ham&nbsp; (-0.4 points, 5.0 required)</p><p> pts rule name&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; description<br />---- ---------------------- --------------------------------------------------<br />-0.0 SPF_PASS&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;SPF: sender matches SPF record<br />-2.6 BAYES_00&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;BODY: Bayesian spam probability is 0 to 1%<br />&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; [score: 0.0000]<br /> 2.2 TVD_SPACE_RATIO&nbsp; &nbsp; &nbsp; &nbsp; BODY: TVD_SPACE_RATIO</p><p>in both cases one check fails, any solutions or hints for that failing test?<br />also any suggestion, tip, hint for the different behavior?</p>]]></content>
			<author>
				<name><![CDATA[BigMichi1]]></name>
				<uri>http://www.iredmail.org/forum/user295.html</uri>
			</author>
			<updated>2009-11-14T13:45:03Z</updated>
			<id>http://www.iredmail.org/forum/post1815.html#p1815</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: DKIM Mail signing]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/post1806.html#p1806" />
			<content type="html"><![CDATA[<div class="quotebox"><cite>BigMichi1 wrote:</cite><blockquote><p>i sent now mail through horde imp webmail frontend and got this message header:</p></blockquote></div><p>Are you add the horde yourslef ? you can try to use roundcube test it.</p>]]></content>
			<author>
				<name><![CDATA[shake]]></name>
				<uri>http://www.iredmail.org/forum/user3.html</uri>
			</author>
			<updated>2009-11-13T04:13:52Z</updated>
			<id>http://www.iredmail.org/forum/post1806.html#p1806</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: DKIM Mail signing]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/post1801.html#p1801" />
			<content type="html"><![CDATA[<p>Are you sure they are not signed? Most mail servers only check the DKIM signature and then discard it, so the client can&#039;t see it. Send a mail to yahoo.com, they don&#039;t discard it.</p><p>Also, check amavisd.conf and make sure dkim email signing is enabled for outgoing.</p><p>LE:</p><p>Please use all reflectors from this page:</p><p><a href="http://testing.dkim.org/reflector.html">http://testing.dkim.org/reflector.html</a></p>]]></content>
			<author>
				<name><![CDATA[maxie_ro]]></name>
				<uri>http://www.iredmail.org/forum/user381.html</uri>
			</author>
			<updated>2009-11-12T11:49:51Z</updated>
			<id>http://www.iredmail.org/forum/post1801.html#p1801</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: DKIM Mail signing]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/post1799.html#p1799" />
			<content type="html"><![CDATA[<p>Could you please try to send a mail via MUA like Outlook or Thunderbird? Not webmail this time.</p>]]></content>
			<author>
				<name><![CDATA[ZhangHuangbin]]></name>
				<uri>http://www.iredmail.org/forum/user2.html</uri>
			</author>
			<updated>2009-11-12T07:35:33Z</updated>
			<id>http://www.iredmail.org/forum/post1799.html#p1799</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: DKIM Mail signing]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/post1797.html#p1797" />
			<content type="html"><![CDATA[<p>i sent now mail through horde imp webmail frontend and got this message header:</p><p>Received: from [188.40.84.226] (helo=mail.bigmichi1.de)<br />by mx38.web.de with esmtp (WEB.DE 4.110 #314)<br />id 1N8Tzz-0000ur-00<br />for bigmichi1@web.de; Thu, 12 Nov 2009 08:21:43 +0100<br />Received: by mail.bigmichi1.de (iRedMail, from userid 33)<br />id EEA957CE4; Thu, 12 Nov 2009 08:22:36 +0100 (CET)<br />Received: from mail.salt-solutions.de (mail.salt-solutions.de<br />[217.7.51.164]) by horde.bigmichi1.de (Horde Framework) with HTTP; Thu, 12<br />Nov 2009 08:22:36 +0100<br />Message-ID: &lt;20091112082236.18626y8zeyr0egn0@horde.bigmichi1.de&gt;<br />X-Priority: 3 (Normal)<br />Date: Thu, 12 Nov 2009 08:22:36 +0100<br />From: Michael Cramer &lt;michael@bigmichi1.de&gt;<br />To: bigmichi1@web.de<br />Subject: Testmail<br />MIME-Version: 1.0<br />Content-Disposition: inline<br />User-Agent: Internet Messaging Program (IMP) H3 (4.3.5)<br />Return-Path: michael@bigmichi1.de<br />Content-Type: text/plain; charset=&quot;iso-8859-15&quot;<br />Content-Transfer-Encoding: 8bit</p><p>no dkim at all</p>]]></content>
			<author>
				<name><![CDATA[BigMichi1]]></name>
				<uri>http://www.iredmail.org/forum/user295.html</uri>
			</author>
			<updated>2009-11-12T07:23:39Z</updated>
			<id>http://www.iredmail.org/forum/post1797.html#p1797</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: DKIM Mail signing]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/post1796.html#p1796" />
			<content type="html"><![CDATA[<div class="quotebox"><cite>BigMichi1 wrote:</cite><blockquote><p>mail sending is done from console with simple mail command on debian 5.0.3.</p></blockquote></div><p>Could you please try to send mail via MUA or webmail?</p>]]></content>
			<author>
				<name><![CDATA[ZhangHuangbin]]></name>
				<uri>http://www.iredmail.org/forum/user2.html</uri>
			</author>
			<updated>2009-11-12T07:02:40Z</updated>
			<id>http://www.iredmail.org/forum/post1796.html#p1796</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: DKIM Mail signing]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/post1795.html#p1795" />
			<content type="html"><![CDATA[<p>there are more than 3 GB free, are there any ways to debug signing to to print some verbose messages to a log file?</p>]]></content>
			<author>
				<name><![CDATA[BigMichi1]]></name>
				<uri>http://www.iredmail.org/forum/user295.html</uri>
			</author>
			<updated>2009-11-12T06:55:15Z</updated>
			<id>http://www.iredmail.org/forum/post1795.html#p1795</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: DKIM Mail signing]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/post1794.html#p1794" />
			<content type="html"><![CDATA[<p>chek your server memory, if the memory run out. would lead to the dkim not sign.</p><p>I have test in debian 5.01 and iredmail 0.51 , and have no problem. </p><p>sent email to gmail can find dkim head.</p>]]></content>
			<author>
				<name><![CDATA[shake]]></name>
				<uri>http://www.iredmail.org/forum/user3.html</uri>
			</author>
			<updated>2009-11-11T16:11:42Z</updated>
			<id>http://www.iredmail.org/forum/post1794.html#p1794</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: DKIM Mail signing]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/post1793.html#p1793" />
			<content type="html"><![CDATA[<p>it is not the problem to get the key and enter it to the dns zone file, the problem is that messages are not signed by dkim no header information at all. dns entry is verified by amavisd testkeys which shows PASS</p>]]></content>
			<author>
				<name><![CDATA[BigMichi1]]></name>
				<uri>http://www.iredmail.org/forum/user295.html</uri>
			</author>
			<updated>2009-11-11T13:04:54Z</updated>
			<id>http://www.iredmail.org/forum/post1793.html#p1793</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: DKIM Mail signing]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/post1792.html#p1792" />
			<content type="html"><![CDATA[<p>You need to put the correct entries in the nameserver(s) that&#039;s holding your domain.</p><p>E.g.:<br /></p><div class="codebox"><pre><code>dkim._domainkey.yourdomain.com.        3600 TXT (
  &quot;v=DKIM1; p=&quot;
  &quot;MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDYwEXrQqGpvGm3TS7O3oob6Plh&quot;
  [....................]
_adsp._domainkey.yourdomain.com. IN    TXT    &quot;dkim=all&quot;</code></pre></div><p>You can find the generated DKIM key for your domain:<br /></p><div class="codebox"><pre><code>[root@mx2 ~]# amavisd showkeys yourdomain.com
; key#16, domain yourdomain.com, /var/lib/dkim/yourdomain.com.pem
dkim._domainkey.yourdomain.com.        3600 TXT (
  &quot;v=DKIM1; p=&quot;
  &quot;MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDYwEXrQqGpvGm3TS7O3oob6Plh&quot;
  [....................]</code></pre></div><p>and copy/paste it from there to your zone file.</p>]]></content>
			<author>
				<name><![CDATA[maxie_ro]]></name>
				<uri>http://www.iredmail.org/forum/user381.html</uri>
			</author>
			<updated>2009-11-11T10:51:32Z</updated>
			<id>http://www.iredmail.org/forum/post1792.html#p1792</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[DKIM Mail signing]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/post1791.html#p1791" />
			<content type="html"><![CDATA[<p>Hi,</p><p>i followed the guide to set up iredmail and also choose to include spf and dkim. i set up my dns records for both spf and dkim like mentioned here <a href="http://code.google.com/p/iredmail/wiki/DNS_DKIM">http://code.google.com/p/iredmail/wiki/DNS_DKIM</a> and here <a href="http://code.google.com/p/iredmail/wiki/DNS_SPF.">http://code.google.com/p/iredmail/wiki/DNS_SPF.</a> but when i sent mail they are not signed with dkim, there are no header entries in the mail? amavisd-new testkeys show pass. must there something more be done to get this working? spf is working really good for me. i tested both with sending a mail to check-auth@verifier.port25.com and they also say that the mail is not dkim signed. mail sending is done from console with simple mail command on debian 5.0.3. Any help would be great to get that working.</p><p>Regards</p>]]></content>
			<author>
				<name><![CDATA[BigMichi1]]></name>
				<uri>http://www.iredmail.org/forum/user295.html</uri>
			</author>
			<updated>2009-11-11T10:44:03Z</updated>
			<id>http://www.iredmail.org/forum/post1791.html#p1791</id>
		</entry>
</feed>
