Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 5 Sep 2018 16:00:01 -0400
From:      William Dudley <wfdudley@gmail.com>
To:        John Levine <johnl@iecc.com>
Cc:        freebsd-questions <freebsd-questions@freebsd.org>
Subject:   Re: DKIM is driving me nuts
Message-ID:  <CAFsnNZ+qeK+M1PPFns59wDeH_Y+-3VDmkwN-iZAEU7qcHS8oRA@mail.gmail.com>
In-Reply-To: <20180905180704.89453200414382@ary.local>
References:  <CAFsnNZ+HXxrn7+3sYxWtBuA1+rCjvhbtrAg6Y5Tkm_icAte-fg@mail.gmail.com> <20180905180704.89453200414382@ary.local>

Next in thread | Previous in thread | Raw E-Mail | Index | Archive | Help
No, this is not that case.

This is the simplest possible use-case:

type "Mail wfdudley@gmail.com" on the command line of my casano.com server
and send a simple one line email with DKIM signing turned on.

Google (and others) say the message fails DKIM "bad signature".

Send the identical message from Thunderbird, and the message passes DKIM
checks at the other end.

Something is different between using Mail/mailx and using Thunderbird,
and I've given up trying to figure out what.

The fact that the intersection of Mailman and DKIM requires more black-art
stuff just re-inforces my decision to give up on DKIM.

Thanks,
Bill Dudley


This email is free of malware because I run Linux.

On Wed, Sep 5, 2018 at 2:07 PM, John Levine <johnl@iecc.com> wrote:

> In article <CAFsnNZ+HXxrn7+3sYxWtBuA1+rCjvhbtrAg6Y5Tkm_icAte-fg@
> mail.gmail.com> you write:
> >1. It's "impossible" (read: "I'm not spending any more time on this") to
> >get DKIM
> >working with different MUAs.  I can get it to work when I send email using
> >Thunderbird,
> >but not when I send email from the command line (mailx).  "Works" means
> >that the
> >inserted DKIM headers pass the checks at the other end.
>
> If they're failing because it says "message has been modfied" that
> should be all the hint you need.  Sendmail conflates submission and
> relay, and has a sometimes unfortunate tendency to helpfully clean up
> message headers on the way through, which of course breaks DKIM
> signatures.  I haven't run sendmail in 20 years but as I recall there
> should be some way to run submitted mail through sendmail once to
> clean up the headers, then DKIM sign it, then send it along for relay.
> That's what everyone else does.
>
> R's,
> John
>



Want to link to this message? Use this URL: <http://docs.FreeBSD.org/cgi/mid.cgi?CAFsnNZ+qeK+M1PPFns59wDeH_Y+-3VDmkwN-iZAEU7qcHS8oRA>