Questions tagged [dkim]

DomainKeys Identified Mail (DKIM) is a method for associating a domain name to an email message, thereby allowing a person, role, or organization to claim some responsibility for the message. The association is set up by means of a digital signature which can be validated by recipients.

DomainKeys Identified Mail (DKIM) is an email authentication method designed to detect forged sender addresses in emails (email spoofing), a technique often used in phishing and email spam.

DKIM allows the receiver to check that an email claimed to have come from a specific domain was indeed authorized by the owner of that domain. It achieves this by affixing a digital signature, linked to a domain name, to each outgoing email message. The recipient system can verify this by looking up the sender's public key published in the DNS. A valid signature also guarantees that some parts of the email (possibly including attachments) have not been modified since the signature was affixed. Usually, DKIM signatures are not visible to end-users, and are affixed or verified by the infrastructure rather than the message's authors and recipients.

The first version of DKIM synthesized and enhanced Yahoo!'s DomainKeys and Cisco's Identified Internet Mail specifications. It was the result of a year-long collaboration among numerous industry players, during 2005, to develop an open-standard e-mail authentication specification. Participants included Alt-N Technologies, AOL, Brandenburg InternetWorking, Cisco, EarthLink, IBM, Microsoft, PGP Corporation, Sendmail, StrongMail Systems, Tumbleweed, VeriSign and Yahoo!. The team produced the initial specification and several implementations. It then submitted the work to the IETF for further enhancement and formal standardization.

(source: Wikipedia)

38 questions
26
votes
1 answer

Do SPF and DKIM TXT records require quotes?

I have been searching for some hours now, but multiple sources say different things. https://support.wordfly.com/hc/en-us/articles/204767474-How-do-we-publish-DKIM-and-SPF-in-our-DNS- States I should not include quotes, whereas…
Neograph734
  • 439
  • 1
  • 4
  • 10
14
votes
3 answers

Sent emails pass SPF and DKIM, but fail DMARC when received by Gmail

Gmail is marking my email messages as Spam. The messages pass SPF and DKIM, but fail DMARC. Is there some way to make my messages pass DMARC? I recently signed up for WordPress hosting at Flywheel, which uses Mandrill for transactional email. My…
nielsbot
  • 243
  • 1
  • 2
  • 6
9
votes
2 answers

Why is google.com trying to send emails from my domain?

I pulled up a DMARC Analyzer report showing emails received on behalf of my domain: In addition to my normal authorized (SPF+DKIM aligned) personal emails from the protonmail.ch domain, there are unauthorized emails coming from the google.com…
Maximillian Laumeister
  • 16,461
  • 3
  • 32
  • 63
8
votes
3 answers

DMARC: SPF Fail, DKIM Pass, Source IP: not mine!

This is an odd one: 65.20.0.12 2 none pass fail
nedge2k
  • 161
  • 1
  • 6
7
votes
1 answer

How to handle duplicate DKIM selectors?

Background When using third party tools which send mails from your domain, you often need to setup DKIM records with selectors defined by the third party. E.g. for MailChimp you're asked to…
JohnLBevan
  • 183
  • 1
  • 6
7
votes
0 answers

SPF and DKIM vs email forwarding addresses: how to avoid being rejected as spam?

Situation: I am sending emails from me@mydomain.com to alice@example.org. My DNS for mydomain.com is correctly configured with an SPF record. The recipient at example.org is able to receive my emails just fine (it says "SPF: pass" in the…
RocketNuts
  • 564
  • 1
  • 5
  • 12
5
votes
4 answers

Do subdomains inherit DKIM keys? Can a DKIM SDID for one domain be used to validly sign mail that appears to be sent from another domain?

Suppose no DKIM keys are defined for sub.example.com, but a key with selector mykey is defined for example.com; that is, a DKIM record exists at mykey._domainkey.example.com in the DNS. Can send mail that is signed using the…
Jivan Pal
  • 189
  • 1
  • 8
5
votes
1 answer

How do email spam filters tell if a spam email was maliciously sent with intent to shutdown a real email address?

So for example, let's say we have a legitimate user from "user@legitimate.com" who sends real emails. However, there is a malicious individual who is using their own server or some other email service to send thousands of spam from…
wlingke
  • 153
  • 3
4
votes
2 answers

Yahoo rejecting email after registrar change

I recently changed registrars and DNS location from Tucows to Cloudflare for one of my domains. During the change, Cloudflare copied my existing DNS records including SPF, DMARC and DKIM keys. The actual email server did not change. Prior to the…
Trebor
  • 3,300
  • 10
  • 25
3
votes
0 answers

WHM's Exim Advanced Editor not accepting settings for DKIM

I'm running Centos 6.7 and WHM 54.0, with Exim running on it: Exim version 4.86_1 #1 built 04-Mar-2016 17:12:16 I'm trying to configure DKIM for my outbound mail, which in part I've mostly got working. The problem I have is that the changes I make…
3
votes
2 answers

Setting up DKIM, SPF, and DMARC Records for Domains that You Won't Use for Email

I have a few domains out there that are never used for email. If you look at the domains, you'll know the company. This makes me wonder, should I set up DMARC, DKIM, and SPF for these domains even though there's no MX record?
3
votes
1 answer

Intermittent DKIM authentication failing

We are recently deploying DMARC and seeking additional details about an issue. DMARC is configured in the most basic way: v=DMARC1; p=none; rua=mailto:dmarcreports@example.com Our primary server signs outgoing messages with DKIM keys but the first…
You Old Fool
  • 483
  • 1
  • 6
  • 18
3
votes
1 answer

DMARC failure on forwarded SharePoint Online emails

I have a client that uses SharePoint Online but insists on using Gmail. Each user has a O365 account with an Exchange Online mailbox and mail flow/delivery options are set to forward all incoming mail to the corresponding user's Gmail address. From…
WillSL
  • 39
  • 1
3
votes
1 answer

DKIM fails for Gmail only. Emails in spam

I've been banging my head at this for 2 days. I've installed a fresh copy of Virtualmin and I enabled DKIM as mentioned in the documentation. Everything went fine. I've added spf and dkim records in my dns as well which were generated by…
Whip
  • 175
  • 1
  • 7
2
votes
2 answers

Are SPF and DKIM records needed when the SMTP IP is marked as a subscriber block?

I have been searching around, but not sure of all the facts I need. Let me explain. I have stayed out of the SMTP game for a while and have become ignorant of the newer developments. Prior to my current IP address, it was a commercial IP address…
closetnoc
  • 32,902
  • 4
  • 46
  • 69
1
2 3