Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 4 Sep 2018 17:41:16 -0400
From:      Jim Ohlstein <>
To:        William Dudley <>
Subject:   Re: DKIM is driving me nuts
Message-ID:  <>
In-Reply-To: <>
References:  <> <> <> <> <> <> <> <>

Next in thread | Previous in thread | Raw E-Mail | Index | Archive | Help
This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
Content-Type: multipart/mixed; boundary="CxTJLnF1jXiFj8oVt7xkeIOMV1DkflP0B";
From: Jim Ohlstein <>
To: William Dudley <>
Message-ID: <>
Subject: Re: DKIM is driving me nuts
References: <>
In-Reply-To: <>

Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: quoted-printable


On 09/04/2018 11:48 AM, William Dudley wrote:
> I have decided to abandon this quest.
> The intersection of DKIM and Mailman is a huge cluster f--k, and will n=
> be sorted out
> any time soon, if ever.
> Since I value the mailing lists I host, and am unwilling to stop those
> services,
> it makes sense to give up on DKIM.

Before you give up on DKIM, it sounds as though this is a Mailman
problem. There are "fixes" for some issues in Mailman (both 2.1 and 3.1)
that can be easily applied.

In short, DKIM is a digital signature using a private key. The signature
can be verified with the public key. If anything in the message is
changed (as Mailman and other list software is apt to do by changing
headers or adding a footer), DKIM will fail. Also, some large freemail
providers (Yahoo and AOL) have published DMARC policies to reject any
emails from them that fail DKIM. Many smaller servers do the same.

Here's the DKIM results from your last email via Gmail:

Authentication-Results: (amavisd-new);
	dkim=3Dfail (2048-bit key) reason=3D"fail (body has been altered)"

More and more large servers are requiring not only DKIM, but DMARC
policies as well. Running a small mail server is only going to get more
cumbersome. Taking down a working system may not be the best choice.

What is the specific problems that this one user is having? Is it that
his emails to the list are being rejected? Or is his mail server at
"" rejecting emails from the list? Can you post the relevant
entries from your mail log (usually /var/log/maillog on FreeBSD)?

> DKIM doesn't solve any problems (except for one poor schmuck who has a =
> email address, that rejects all email without DKIM), I don't find DKIM
> valuable
> enough to fight with it any more.
> Thanks to all for their suggestions.  I have learned somethings, which =
> the point,
> after all.
> Bill Dudley

Jim Ohlstein
Professional Mailman Hosting


Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"




Want to link to this message? Use this URL: <>