# 6.1.0.0gbb8c210e: DKIM fails on auto-generated

**URL:** <https://community.ciphermail.com/t/6-1-0-0gbb8c210e-dkim-fails-on-auto-generated/1015>\
**Category:** Gateway\
**Created:** [September 29, 2025, 11:08am UTC](https://community.ciphermail.com/t/6-1-0-0gbb8c210e-dkim-fails-on-auto-generated/1015 "2025-09-29T11:08:26Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![cheater2](https://avatars.discourse-cdn.com/v4/letter/c/9dc877/32.png) [@cheater2](https://community.ciphermail.com/u/cheater2)\
**Post date:** [September 29, 2025, 11:08am UTC](https://community.ciphermail.com/t/6-1-0-0gbb8c210e-dkim-fails-on-auto-generated/1015/1 "2025-09-29T11:08:26Z")

</div>

DKIM signing fails when the system itself sends emails.

Failure refers to the fact that the email is first processed with my domain key and then with a fixed key and a completely custom signing template.

This also changes the header, and nothing matches my key anymore.

The following is added:  
**`X-Keep-CipherMail-DKIM-Signature`** `:`  
` a=rsa-sha256;`  
` b=[manually removed]`  
` c=relaxed/relaxed; s=selector; d=CipherMail; v=1;`  
` bh=FNFzXw6nBYmrYyoERf1j4O62pd4OwZvtVKnotoFkRB0=;`  
` h=From:X-Keep-CipherMail-Auto-Submitted;`

How can I prevent the final, pointless DKIM signing from being performed with some random key? (Emails that are not sent by the system itself but only “pass through” Ciphermail are correctly signed.)

---

<div class="post-metadata">

**Author:** ![martijn](https://dub1.discourse-cdn.com/flex017/user_avatar/community.ciphermail.com/martijn/32/127_2.png) [@martijn](https://community.ciphermail.com/u/martijn)\
**Post date:** [September 29, 2025, 11:33am UTC](https://community.ciphermail.com/t/6-1-0-0gbb8c210e-dkim-fails-on-auto-generated/1015/2 "2025-09-29T11:33:02Z")

</div>

**X-Keep-CipherMail-DKIM-Signature** is **not** a DKIM header but a custom CipherMail header and therefore should not result in DKIM failure unless you have a very broken DKIM verifier.

**X-Keep-CipherMail-DKIM-Signature** is used to prevent mailloops when email is being forwarded again through the gateway (which in typical setups never happens).

The most likely reason for the DKIM failure is that you generate a DKIM signature before the gateway handles the message.

---

<div class="post-metadata">

**Author:** ![cheater2](https://avatars.discourse-cdn.com/v4/letter/c/9dc877/32.png) [@cheater2](https://community.ciphermail.com/u/cheater2)\
**Post date:** [September 29, 2025, 12:04pm UTC](https://community.ciphermail.com/t/6-1-0-0gbb8c210e-dkim-fails-on-auto-generated/1015/3 "2025-09-29T12:04:54Z")

</div>

> [@martijn](#):
>
> X-Keep

It only affects the email sent when I have enabled “pdf Portal auto signup” in the general settings.  
In the logs, I see that the same email is DKIM signed twice.

No DKIM signing is performed anywhere else in my server setup.  
My key is only stored in Ciphermail.  
And this signing works perfectly for normal emails. These emails also lack the “X-Keep…” from Ciphermail itself, and the log shows only one(!) entry for a DKIM signing.

But none of this is the case when the system itself sends the email.

If it claims that this email passes through the gateway twice: Is this auto-generated email injected on port 10025? Then I wouldn’t be surprised, since your Postfix template specifies reinjection on port 10026.

---

<div class="post-metadata">

**Author:** ![martijn](https://dub1.discourse-cdn.com/flex017/user_avatar/community.ciphermail.com/martijn/32/127_2.png) [@martijn](https://community.ciphermail.com/u/martijn)\
**Post date:** [September 29, 2025, 12:25pm UTC](https://community.ciphermail.com/t/6-1-0-0gbb8c210e-dkim-fails-on-auto-generated/1015/4 "2025-09-29T12:25:24Z")

</div>

Where is DKIM signing applied? In the CipherMail gateway? Or somewhere else?

---

<div class="post-metadata">

**Author:** ![martijn](https://dub1.discourse-cdn.com/flex017/user_avatar/community.ciphermail.com/martijn/32/127_2.png) [@martijn](https://community.ciphermail.com/u/martijn)\
**Post date:** [September 29, 2025, 12:39pm UTC](https://community.ciphermail.com/t/6-1-0-0gbb8c210e-dkim-fails-on-auto-generated/1015/5 "2025-09-29T12:39:11Z")

</div>

You might be right. Can you try the following?

Remove the date from the DKIM signature for the global settings:

So from

```auto
v=1; c=relaxed/relaxed; s=ciphermail; d=${domain}; h=From:Subject:To:Date; a=rsa-sha256; t=; bh=; b=;

```

```auto
v=1; c=relaxed/relaxed; s=ciphermail; d=${domain}; h=From:Subject:To; a=rsa-sha256; t=; bh=; b=;

```

---

<div class="post-metadata">

**Author:** ![martijn](https://dub1.discourse-cdn.com/flex017/user_avatar/community.ciphermail.com/martijn/32/127_2.png) [@martijn](https://community.ciphermail.com/u/martijn)\
**Post date:** [September 29, 2025, 2:31pm UTC](https://community.ciphermail.com/t/6-1-0-0gbb8c210e-dkim-fails-on-auto-generated/1015/6 "2025-09-29T14:31:44Z")

</div>

I think I found the reason DKIM fails.

Locally generated notifications may fail DKIM verification if the message is  
sent without a Date header. In this case, Postfix automatically inserts a Date  
header (because local\_header\_rewrite\_clients matches), which changes the headers  
after the message was signed. Since the Date header is included in the DKIM  
signature, this modification invalidates the signature. To prevent this, I  
updated the code that sends locally generated email notifications to always add  
a Date header.

I will release a new version of the gateway soon.

Thanks for reporting!

---

<div class="post-metadata">

**Author:** ![cheater2](https://avatars.discourse-cdn.com/v4/letter/c/9dc877/32.png) [@cheater2](https://community.ciphermail.com/u/cheater2)\
**Post date:** [September 29, 2025, 3:07pm UTC](https://community.ciphermail.com/t/6-1-0-0gbb8c210e-dkim-fails-on-auto-generated/1015/7 "2025-09-29T15:07:18Z")

</div>

I tried it, but it didn’t help.

The problem is the following in the headers (I removed sensitive data):

**`MIME-Version`** `: 1.0`  
**`DKIM-Signature`** `: a=rsa-sha256; b=[…….]; c=relaxed/simple; s=default; d=exampledomain.com; t=1759157536; v=1; bh=8PuZdayAV20mHWOtPurOschuQjDO5llTADNT2166I9o=; h=From:Subject:To:Date:Message-ID;`  
**`X-Keep-CipherMail-DKIM-Signature`** `:`  
` a=rsa-sha256;`  
` b=[…….];`  
` c=relaxed/relaxed; s=selector; d=CipherMail; v=1;`  
` bh=hYn+rsmvxAeBolVeuQauHPeZmOOtWsLPcpnTtE1Gam8=;`  
` h=From:X-Keep-CipherMail-Auto-Submitted;`

Two different keys are being used. One is the one I generated, and another (X-KEEP…) is hard-coded somewhere.  
I don’t understand the purpose of DKIM signing to prevent a loop. For this, you can set additional headers like “Ciphermail-processed: True,” but you don’t use internal DKIM signing, which in turn invalidates a necessary external “real” DKIM signing… This contradicts the purpose of DKIM. (`d=Ciphermail` alone is an invalid domain…)

---

<div class="post-metadata">

**Author:** ![martijn](https://dub1.discourse-cdn.com/flex017/user_avatar/community.ciphermail.com/martijn/32/127_2.png) [@martijn](https://community.ciphermail.com/u/martijn)\
**Post date:** [September 29, 2025, 3:12pm UTC](https://community.ciphermail.com/t/6-1-0-0gbb8c210e-dkim-fails-on-auto-generated/1015/8 "2025-09-29T15:12:28Z")

</div>

**`X-Keep-CipherMail-DKIM-Signature`** is **not** causing DKIM failures. This is a private header and is not related to DKIM sigantures.

Did you change the default DKIM template in CipherMail? If not, then the following header was not generated by CipherMail back-end.

```auto
DKIM-Signature: a=rsa-sha256; b=[…….]; c=relaxed/simple; s=default; d=exampledomain.com; t=1759157536; v=1; bh=8PuZdayAV20mHWOtPurOschuQjDO5llTADNT2166I9o=; h=From:Subject:To:Date:Message-ID;

```

The default DKIM template used by CipherMail is set to:

```auto
v=1; c=relaxed/relaxed; s=ciphermail; d=${domain}; h=From:Subject:To:Date; a=rsa-sha256; t=; bh=; b=;

```

This template does not contain the `Message-ID` header. Or did you explicitly added this header?

---

<div class="post-metadata">

**Author:** ![cheater2](https://avatars.discourse-cdn.com/v4/letter/c/9dc877/32.png) [@cheater2](https://community.ciphermail.com/u/cheater2)\
**Post date:** [September 29, 2025, 3:19pm UTC](https://community.ciphermail.com/t/6-1-0-0gbb8c210e-dkim-fails-on-auto-generated/1015/9 "2025-09-29T15:19:26Z")

</div>

I think the timing of DKIM signing, which, for example, was set in the “Domain Menu” in my case, is incorrect. I suspect that with Ciphermail’s backend, the DKIM signing stored in the domain is performed first and then passed on to the process that inserts the internal, hard-coded signing with the “X-Keep-” header.

Regarding your question about the DKIM signature header: This is inserted by CipherMail. There is no other entity that performs DKIM.

Of course, I have to adapt the template for my domain and my requirements.

Try it yourself. Use a valid email server with a public domain and create a DKIM, enter all the required information in the DNS, and then send an email via the gateway. The email containing the encrypted PDF is signed correctly. The second one with the subject “Signup for the CipherMail Secure Email Portal” is DKIM-invalid.

---

<div class="post-metadata">

**Author:** ![cheater2](https://avatars.discourse-cdn.com/v4/letter/c/9dc877/32.png) [@cheater2](https://community.ciphermail.com/u/cheater2)\
**Post date:** [September 29, 2025, 3:23pm UTC](https://community.ciphermail.com/t/6-1-0-0gbb8c210e-dkim-fails-on-auto-generated/1015/10 "2025-09-29T15:23:54Z")

</div>

![Bildschirmfoto 2025-09-29 um 17.21.17](https://europe1.discourse-cdn.com/flex017/uploads/ciphermail/original/1X/8649389785a2e9b53ba82737d1a0dbffa64f5094.png)

---

<div class="post-metadata">

**Author:** ![martijn](https://dub1.discourse-cdn.com/flex017/user_avatar/community.ciphermail.com/martijn/32/127_2.png) [@martijn](https://community.ciphermail.com/u/martijn)\
**Post date:** [September 29, 2025, 3:31pm UTC](https://community.ciphermail.com/t/6-1-0-0gbb8c210e-dkim-fails-on-auto-generated/1015/11 "2025-09-29T15:31:08Z")

</div>

You changed the DKIM template for a user or domain. Is that on purpose? Normally you change this for the global settings because it’s now unclear which template is used because it depends on the sender

---

<div class="post-metadata">

**Author:** ![martijn](https://dub1.discourse-cdn.com/flex017/user_avatar/community.ciphermail.com/martijn/32/127_2.png) [@martijn](https://community.ciphermail.com/u/martijn)\
**Post date:** [September 29, 2025, 3:37pm UTC](https://community.ciphermail.com/t/6-1-0-0gbb8c210e-dkim-fails-on-auto-generated/1015/12 "2025-09-29T15:37:49Z")

</div>

Can you post the DKIM template that you are using?

---

<div class="post-metadata">

**Author:** ![cheater2](https://avatars.discourse-cdn.com/v4/letter/c/9dc877/32.png) [@cheater2](https://community.ciphermail.com/u/cheater2)\
**Post date:** [September 29, 2025, 3:51pm UTC](https://community.ciphermail.com/t/6-1-0-0gbb8c210e-dkim-fails-on-auto-generated/1015/13 "2025-09-29T15:51:58Z")

</div>

I had previously changed it to global. Then, according to the documentation, I bound it to a domain when I encountered the problem.

`v=1; c=relaxed/simple; s=default; d=${domain}; h=From:Subject:To:Date:Message-ID; a=rsa-sha256; t=; bh=; b=;`

---

<div class="post-metadata">

**Author:** ![martijn](https://dub1.discourse-cdn.com/flex017/user_avatar/community.ciphermail.com/martijn/32/127_2.png) [@martijn](https://community.ciphermail.com/u/martijn)\
**Post date:** [September 29, 2025, 3:53pm UTC](https://community.ciphermail.com/t/6-1-0-0gbb8c210e-dkim-fails-on-auto-generated/1015/14 "2025-09-29T15:53:41Z")

</div>

Can you try changing it on the global level to

```auto
v=1; c=relaxed/relaxed; s=ciphermail; d=${domain}; h=From:Subject; a=rsa-sha256; t=; bh=; b=;

```

And check whether the DKIM signature is then correct?

---

<div class="post-metadata">

**Author:** ![cheater2](https://avatars.discourse-cdn.com/v4/letter/c/9dc877/32.png) [@cheater2](https://community.ciphermail.com/u/cheater2)\
**Post date:** [September 29, 2025, 4:08pm UTC](https://community.ciphermail.com/t/6-1-0-0gbb8c210e-dkim-fails-on-auto-generated/1015/15 "2025-09-29T16:08:03Z")

</div>

I did that, and unfortunately, there was no improvement.

Perhaps the logs will be more helpful – they are signed twice, which isn’t the case if the DKIM remains valid. Then the entry “was DKIM signed” appears only once (!) in the logs.

 ![Bildschirmfoto 2025-09-29 um 18.00.36](https://europe1.discourse-cdn.com/flex017/uploads/ciphermail/original/1X/5e62a9dd4b58ad3c4898db86fab8103324c7205f.jpeg)

---

<div class="post-metadata">

**Author:** ![cheater2](https://avatars.discourse-cdn.com/v4/letter/c/9dc877/32.png) [@cheater2](https://community.ciphermail.com/u/cheater2)\
**Post date:** [September 29, 2025, 4:13pm UTC](https://community.ciphermail.com/t/6-1-0-0gbb8c210e-dkim-fails-on-auto-generated/1015/16 "2025-09-29T16:13:40Z")

</div>

At the end, see which instance is active. `DKIMSign` comes last, and `SenderPropertyDKIMSign` comes first.

Emails with correct DKIM are missing `DKIMSign`, and only `SenderPropertyDKIMSign` is present.

---

<div class="post-metadata">

**Author:** ![martijn](https://dub1.discourse-cdn.com/flex017/user_avatar/community.ciphermail.com/martijn/32/127_2.png) [@martijn](https://community.ciphermail.com/u/martijn)\
**Post date:** [September 29, 2025, 6:22pm UTC](https://community.ciphermail.com/t/6-1-0-0gbb8c210e-dkim-fails-on-auto-generated/1015/17 "2025-09-29T18:22:58Z")

</div>

I understand why you think DKIM failure is related to the additional “DKIM” signature (note the quotes to indicate that this is not a DKIM signature) but the DKIM failure is not related to the custom DKIm signature.

May I ask how you configured DKIM? A assume with the CLI?

---

<div class="post-metadata">

**Author:** ![cheater2](https://avatars.discourse-cdn.com/v4/letter/c/9dc877/32.png) [@cheater2](https://community.ciphermail.com/u/cheater2)\
**Post date:** [September 29, 2025, 7:37pm UTC](https://community.ciphermail.com/t/6-1-0-0gbb8c210e-dkim-fails-on-auto-generated/1015/18 "2025-09-29T19:37:12Z")

</div>

Yes, with the CLI.  
I regenerated and retrieved the key in the CLI.

I then entered it in the WebGUI under “Key Pair.”  
Anyway, it works that way – except for the system’s own emails.

---

<div class="post-metadata">

**Author:** ![martijn](https://dub1.discourse-cdn.com/flex017/user_avatar/community.ciphermail.com/martijn/32/127_2.png) [@martijn](https://community.ciphermail.com/u/martijn)\
**Post date:** [September 30, 2025, 1:43pm UTC](https://community.ciphermail.com/t/6-1-0-0gbb8c210e-dkim-fails-on-auto-generated/1015/19 "2025-09-30T13:43:19Z")

</div>

We released an update (6.2.2) which should fix the issue. We also included documentation for configuring DKIM. We made the system DKIM key hidden (i.e., no longer shown from the UI) because it was confusing.

> **[6.2.2 · CipherMail B.V. / ciphermail-community-gateway · GitLab](https://gitlab.com/ciphermail/ciphermail-community-gateway/-/releases/6.2.2)**
>
> This repository contains the 'open core' code that powers the CipherMail Email Encryption Gateway. It contains everything you need to build the libraries and OS packages of the...

> **[DKIM — CipherMail Documentation](https://www.ciphermail.com/documentation/gateway-administration-guide/dkim.html)**

---

<div class="post-metadata">

**Author:** ![cheater2](https://avatars.discourse-cdn.com/v4/letter/c/9dc877/32.png) [@cheater2](https://community.ciphermail.com/u/cheater2)\
**Post date:** [September 30, 2025, 3:50pm UTC](https://community.ciphermail.com/t/6-1-0-0gbb8c210e-dkim-fails-on-auto-generated/1015/20 "2025-09-30T15:50:26Z")

</div>

Okay. The release fixed it.

I didn’t change anything with the key, though. I simply installed the .deb packages and tried it out.

Thanks for the update. And also for the very quick response.  
I’d be interested to know what the cause of the problem was? But only if there’s time to explain it 😉

[Next page](https://community.ciphermail.com/t/6-1-0-0gbb8c210e-dkim-fails-on-auto-generated/1015.md?page=2)
