# DKIM

**URL:** <https://community.ciphermail.com/t/dkim/496>\
**Category:** Gateway\
**Created:** [March 24, 2016, 7:35pm UTC](https://community.ciphermail.com/t/dkim/496 "2016-03-24T19:35:57Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Matthias\_Henze](https://avatars.discourse-cdn.com/v4/letter/m/9e8a1a/32.png) [@Matthias\_Henze](https://community.ciphermail.com/u/Matthias_Henze)\
**Post date:** [March 24, 2016, 7:35pm UTC](https://community.ciphermail.com/t/dkim/496/1 "2016-03-24T19:35:57Z")

</div>

Hi,

my mail server (Kerio) can apply DKIM signatures. Piping DKIM signed  
mails through Ciphermail disrupts the validity of the DKIM signatures.  
Postfix on the Ciphermail server has to apply the DKIM signature after  
the mail was processd by Ciphermail. This could be achieved by following  
these howtos:

[https://www.digitalocean.com/community/tutorials/how-to-install-and-configure-dkim-with-postfix-on-debian-wheezy](https://www.digitalocean.com/community/tutorials/how-to-install-and-configure-dkim-with-postfix-on-debian-wheezy)

[http://unixwars.blogspot.de/2015/01/8bitmime-and-dkim-body-authentication.html](http://unixwars.blogspot.de/2015/01/8bitmime-and-dkim-body-authentication.html)

The second is required at my site because without it mails sent by  
Thunderbird fail validation by remote servers. My master.cf now looks  
like this:

smtp inet n - - - - smtpd  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;-o  
message\_size\_limit=${djigzo\_before\_filter\_message\_size\_limit}  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;-o content\_filter=smtp-downconvert:127.0.0.1:10026  
pickup fifo n - - 60 1 pickup  
...  
...  
...  
# cleanup for reinject so we can set the hopcount\_limit differently for  
the reinjection port  
cleanup\_reinject unix n - - - 0 cleanup  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;-o hopcount\_limit=100

smtp-downconvert unix - - - - 2 smtp  
&nbsp;&nbsp;&nbsp;&nbsp;-o smtp\_discard\_ehlo\_keywords=8bitmime,silent-discard

127.0.0.1:10026 inet n - n - 10 smtpd  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;-o content\_filter=  
...  
...  
...

Suggestion: Add a DKIM config option to Ciphermail 🙂

cheers  
Matthias

> **···**
>
> --
> 
> MHC SoftWare GmbH  
> Fichtera 17  
> 96274 Itzgrund/Germany
> 
> voice: +49-(0)9533-92006-0  
> fax: +49-(0)9533-92006-6  
> e-mail: info(a)mhcsoftware.de
> 
> HR Coburg: B2242  
> Geschäftsführer: Matthias Henze

---

<div class="post-metadata">

**Author:** ![Matthias\_Henze](https://avatars.discourse-cdn.com/v4/letter/m/9e8a1a/32.png) [@Matthias\_Henze](https://community.ciphermail.com/u/Matthias_Henze)\
**Post date:** [March 27, 2016, 2:07pm UTC](https://community.ciphermail.com/t/dkim/496/2 "2016-03-27T14:07:38Z")

</div>

Hi,

my first approach with "opendkim" does not work as "opendkim" uses  
milter and Ciphermail is a content filter. Milters are applied before  
content filters and the s/Mime signature modifies the body of the mail  
with the signature. This invalidates the DKIM signature. Took ma a day  
to figure this out as I was not aware of the described processing order.  
Finally I found this out just by reading the (previously ignored)  
headlines of [Postfix After-Queue Content Filter](http://www.postfix.org/FILTER_README.html) and  
www.postfix.org/MILTER\_README.html 🙂

See [postfix\_dkim\_support [MHC SoftWare Wiki]](https://wiki.mhcsoftware.de/postfix_dkim_support) (sorry, German) for  
details.

cheers  
Matthias

> **···**
>
> Am 24.03.2016 um 20:35 schrieb Matthias Henze:
> 
> > Hi,
> > 
> > my mail server (Kerio) can apply DKIM signatures. Piping DKIM signed  
> > mails through Ciphermail disrupts the validity of the DKIM signatures.  
> > Postfix on the Ciphermail server has to apply the DKIM signature after  
> > the mail was processd by Ciphermail. This could be achieved by following  
> > these howtos:
> > 
> > [How To Install and Configure DKIM with Postfix on Debian Wheezy | DigitalOcean](https://www.digitalocean.com/community/tutorials/how-to-install-and-configure-dkim-with-postfix-on-debian-wheezy)
> > 
> > [Record of the UNIX Wars: Email fun: 8BITMIME and DKIM body authentication failure](http://unixwars.blogspot.de/2015/01/8bitmime-and-dkim-body-authentication.html)
> > 
> > The second is required at my site because without it mails sent by  
> > Thunderbird fail validation by remote servers. My master.cf now looks  
> > like this:
> > 
> > smtp inet n - - - - smtpd  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;-o  
> > message\_size\_limit=${djigzo\_before\_filter\_message\_size\_limit}  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;-o content\_filter=smtp-downconvert:127.0.0.1:10026  
> > pickup fifo n - - 60 1 pickup  
> > ...  
> > ...  
> > ...  
> > # cleanup for reinject so we can set the hopcount\_limit differently for  
> > the reinjection port  
> > cleanup\_reinject unix n - - - 0 cleanup  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;-o hopcount\_limit=100
> > 
> > smtp-downconvert unix - - - - 2 smtp  
> > &nbsp;&nbsp;&nbsp;&nbsp;-o smtp\_discard\_ehlo\_keywords=8bitmime,silent-discard
> > 
> > 127.0.0.1:10026 inet n - n - 10 smtpd  
> > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;-o content\_filter=  
> > ...  
> > ...  
> > ...
> > 
> > Suggestion: Add a DKIM config option to Ciphermail 🙂
> > 
> > cheers  
> > Matthias
> 
> --
> 
> MHC SoftWare GmbH  
> Fichtera 17  
> 96274 Itzgrund/Germany
> 
> voice: +49-(0)9533-92006-0  
> fax: +49-(0)9533-92006-6  
> e-mail: info(a)mhcsoftware.de
> 
> HR Coburg: B2242  
> Geschaeftsfuehrer: Matthias Henze

---

<div class="post-metadata">

**Author:** ![martijn](https://dub1.discourse-cdn.com/flex017/user_avatar/community.ciphermail.com/martijn/32/127_2.png) [@martijn](https://community.ciphermail.com/u/martijn)\
**Post date:** [March 27, 2016, 2:29pm UTC](https://community.ciphermail.com/t/dkim/496/3 "2016-03-27T14:29:56Z")

</div>

> my first approach with "opendkim" does not work as "opendkim" uses  
> milter and Ciphermail is a content filter. Milters are applied before  
> content filters and the s/Mime signature modifies the body of the mail  
> with the signature. This invalidates the DKIM signature. Took ma a day  
> to figure this out as I was not aware of the described processing order.  
> Finally I found this out just by reading the (previously ignored)  
> headlines of [Postfix After-Queue Content Filter](http://www.postfix.org/FILTER_README.html) and  
> www.postfix.org/MILTER\_README.html 🙂

Adding the DKIM milter on the reinjection port(s) should work. After  
handling the mail (i.e., encryption/decryption etc), the back-end sends  
the mail back to postfix on a "reinjection port" (port 10026).

I haven't tested it but the following might work:

See the following line in master under the 127.0.0.1:10026 section:

-o  
receive\_override\_options=no\_unknown\_recipient\_checks,no\_header\_body\_checks,no\_milters

You should change this line to something like:

-o  
receive\_override\_options=no\_unknown\_recipient\_checks,no\_header\_body\_checks,smtpd\_milters=REPLACEWITHDKIMMILTER

This should enable the DKIM milet after the message has been  
encryped/decrypted/signed.

Again, I have not tested this but this should work (might some minimal  
changes though)

Then again, you suggestion of using dkimproxy is also a good alternative  
until DKIM support has been added to CipherMail\*.

Kind regards,

Martijn Brinkers

\* "native" DKIM support is basically working but not enabled for all  
SMTP outgoing mail. We will see whether we can make it possible to  
enable this for all outgoing email.

> **···**
>
> On 03/27/2016 04:07 PM, Matthias Henze wrote:
> 
> > See [postfix\_dkim\_support [MHC SoftWare Wiki]](https://wiki.mhcsoftware.de/postfix_dkim_support) (sorry, German) for  
> > details.
> > 
> > cheers  
> > Matthias
> > 
> > Am 24.03.2016 um 20:35 schrieb Matthias Henze:
> > 
> > > Hi,
> > > 
> > > my mail server (Kerio) can apply DKIM signatures. Piping DKIM signed  
> > > mails through Ciphermail disrupts the validity of the DKIM signatures.  
> > > Postfix on the Ciphermail server has to apply the DKIM signature after  
> > > the mail was processd by Ciphermail. This could be achieved by following  
> > > these howtos:
> > > 
> > > [How To Install and Configure DKIM with Postfix on Debian Wheezy | DigitalOcean](https://www.digitalocean.com/community/tutorials/how-to-install-and-configure-dkim-with-postfix-on-debian-wheezy)
> > > 
> > > [Record of the UNIX Wars: Email fun: 8BITMIME and DKIM body authentication failure](http://unixwars.blogspot.de/2015/01/8bitmime-and-dkim-body-authentication.html)
> > > 
> > > The second is required at my site because without it mails sent by  
> > > Thunderbird fail validation by remote servers. My master.cf now looks  
> > > like this:
> > > 
> > > smtp inet n - - - - smtpd  
> > > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;-o  
> > > message\_size\_limit=${djigzo\_before\_filter\_message\_size\_limit}  
> > > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;-o content\_filter=smtp-downconvert:127.0.0.1:10026  
> > > pickup fifo n - - 60 1 pickup  
> > > ...  
> > > ...  
> > > ...  
> > > # cleanup for reinject so we can set the hopcount\_limit differently for  
> > > the reinjection port  
> > > cleanup\_reinject unix n - - - 0 cleanup  
> > > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;-o hopcount\_limit=100
> > > 
> > > smtp-downconvert unix - - - - 2 smtp  
> > > &nbsp;&nbsp;&nbsp;&nbsp;-o smtp\_discard\_ehlo\_keywords=8bitmime,silent-discard
> > > 
> > > 127.0.0.1:10026 inet n - n - 10 smtpd  
> > > &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;-o content\_filter=  
> > > ...  
> > > ...  
> > > ...
> > > 
> > > Suggestion: Add a DKIM config option to Ciphermail 🙂
> > > 
> > > cheers  
> > > Matthias
> 
> --  
> CipherMail email encryption
> 
> Email encryption with support for S/MIME, OpenPGP, PDF encryption and  
> secure webmail pull.
> 
> > **[CipherMail email encryption and digital signatures](https://www.ciphermail.com)**
> >
> > Easy to use server-side email encryption for automatic encryption and digital signing of email.
> 
> Twitter: [http://twitter.com/CipherMail](http://twitter.com/CipherMail)

---

<div class="post-metadata">

**Author:** ![Matthias\_Henze](https://avatars.discourse-cdn.com/v4/letter/m/9e8a1a/32.png) [@Matthias\_Henze](https://community.ciphermail.com/u/Matthias_Henze)\
**Post date:** [March 27, 2016, 2:53pm UTC](https://community.ciphermail.com/t/dkim/496/4 "2016-03-27T14:53:46Z")

</div>

> > my first approach with "opendkim" does not work as "opendkim" uses  
> > milter and Ciphermail is a content filter. Milters are applied before  
> > content filters and the s/Mime signature modifies the body of the mail  
> > with the signature. This invalidates the DKIM signature. Took ma a day  
> > to figure this out as I was not aware of the described processing order.  
> > Finally I found this out just by reading the (previously ignored)  
> > headlines of [Postfix After-Queue Content Filter](http://www.postfix.org/FILTER_README.html) and  
> > www.postfix.org/MILTER\_README.html 🙂
> 
> Adding the DKIM milter on the reinjection port(s) should work. After  
> handling the mail (i.e., encryption/decryption etc), the back-end sends  
> the mail back to postfix on a "reinjection port" (port 10026).
> 
> I haven't tested it but the following might work:
> 
> See the following line in master under the 127.0.0.1:10026 section:
> 
> -o  
> receive\_override\_options=no\_unknown\_recipient\_checks,no\_header\_body\_checks,no\_milters
> 
> You should change this line to something like:
> 
> -o  
> receive\_override\_options=no\_unknown\_recipient\_checks,no\_header\_body\_checks,smtpd\_milters=REPLACEWITHDKIMMILTER
> 
> This should enable the DKIM milet after the message has been  
> encryped/decrypted/signed.
> 
> Again, I have not tested this but this should work (might some minimal  
> changes though)

Interesting .. thanks for your reply.

> Then again, you suggestion of using dkimproxy is also a good alternative  
> until DKIM support has been added to CipherMail\*.
> 
> Kind regards,
> 
> Martijn Brinkers
> 
> \* "native" DKIM support is basically working but not enabled for all  
> SMTP outgoing mail. We will see whether we can make it possible to  
> enable this for all outgoing email.

Is there a timeline for new releases and a list of planed features.

A nice feature would be some thing like this:

> **[DropSend | Send Large Files and Email Large Files](https://www.dropsend.com/)**
>
> Send large files with DropSend for free. Email files, store files online, control sends and downloads, and use DropSend for your business.

> **[Email Large Files Free](https://emaillargefile.com)**
>
> Send large files free via email. Upload files, receive link via email. No sign up required.

> **[Send Large Files Free - Fast Secure File Transfer - Filemail](https://www.filemail.com/)**
>
> Send large files free via email and links. Paid accounts share files of any size. Fast secure online file transfer using our file sharing site & apps.

This: [Email Security. Made in Germany. | NoSpamProxy](https://www.nospamproxy.de/en/) offers this feature. There are  
several ways to use it. It requires that a web portal is accessible from  
the Internet. On way is to tell the software to detach the attachments  
of mails, store them and generate a mail for the recipient with a link  
for the download. You also can generate a mail which allows the  
recipient to upload a file, and write a comment. Then you get notified  
by mail and you can download it with a generated link.

Just an idea for a enhancement 🙂

cheers  
Matthias

> **···**
>
> Am 27.03.2016 um 16:29 schrieb Martijn Brinkers:
> 
> > On 03/27/2016 04:07 PM, Matthias Henze wrote:
> 
> --
> 
> MHC SoftWare GmbH  
> Fichtera 17  
> 96274 Itzgrund/Germany
> 
> voice: +49-(0)9533-92006-0  
> fax: +49-(0)9533-92006-6  
> e-mail: info(a)mhcsoftware.de
> 
> HR Coburg: B2242  
> Geschaeftsfuehrer: Matthias Henze

---

<div class="post-metadata">

**Author:** ![Django](https://avatars.discourse-cdn.com/v4/letter/d/e36b37/32.png) [@Django](https://community.ciphermail.com/u/Django)\
**Post date:** [March 27, 2016, 3:43pm UTC](https://community.ciphermail.com/t/dkim/496/5 "2016-03-27T15:43:06Z")

</div>

Hi,

> Is there a timeline for new releases and a list of planed features.

Maybe pushing generated pgpkeys and/or via nsupdate were a grait and usefull feature. Retrieving keys from DNS, too. 🙂

cul8r!  
Django
