Operations grimoire/Mail/DKIM: Difference between revisions
From Nasqueron Agora
< Operations grimoire | Mail
No edit summary |
|||
Line 21: | Line 21: | ||
== Troubleshooting == | == Troubleshooting == | ||
=== Can't load key from … Permission denied === | === Can't load key from … Permission denied === | ||
Keys must | Keys must be readeable to opendkim user. | ||
<source lang="console"> | <source lang="console"> |
Revision as of 14:18, 20 October 2024
Mails are signed with OpenDKIM, an open-source implementation for DKIM.
Add a domain
To create a key with unium
as DKIM selector for <domain.tld>:
$ mkdir /usr/local/etc/opendkim/keys/domain.tld
$ cd /usr/local/etc/opendkim/keys/domain.tld
$ opendkim-genkey -s unium -b 2048 -d domain.tld
$ chown opendkim unium.private
$ cd /usr/local/etc/opendkim
$ make clean all
Test
Send a mail from to another mail server.
You should see a DKIM pass.
You can also from a mailbox for this domain send a mail to check-authverifier.port25.com
Troubleshooting
Can't load key from … Permission denied
Keys must be readeable to opendkim user.
$ chown opendkim /usr/local/etc/opendkim/keys/*/*.private
DKIM must succeed: as long as this isn't fixed, Postfix won't send mail for this domain.