1

Topic: amavis testkeys fail bad RSA signature

==== REQUIRED BASIC INFO OF YOUR IREDMAIL SERVER ====
- iRedMail version (check /etc/iredmail-release): 1.6.2 PGSQL
- Deployed with iRedMail Easy or the downloadable installer? downloadable
- Linux/BSD distribution name and version: Ubuntu 20.04
- Store mail accounts in which backend (LDAP/MySQL/PGSQL): PGSQL
- Web server (Apache or Nginx): Nginx
- Manage mail accounts with iRedAdmin-Pro? No
- [IMPORTANT] Related original log or error message is required if you're experiencing an issue.
====
Hello
Put a new installation, made all the dns settings.
Problem: I can't set up dkim check
  amavisd-new testkeys
TESTING#1 mechta.com.kz: mail._domainkey.mechta.com.kz => fail (bad RSA signature)
And also a log from Yandex
Authentication-Results: vla5-92817046ed8d.qloud-c.yandex.net; spf=pass (vla5-92817046ed8d.qloud-c.yandex.net: domain of mechta.com.kz designates 87.247.24.194 as permitted sender, rule=[a]) smtp.mail=ivan.gafner@mechta.com.kz; dkim=fail header.i=@mechta.com.kz

On the portal dmarcanalyzer it says that the dkim entry is valid
Please help.

----

Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.

2

Re: amavis testkeys fail bad RSA signature

I partially figured out the problem, there was an incorrect entry in the dns, but when reading the header of an incoming letter, the check is also dkim=fail
on the server, the check is successful testcase amavis test=pass

3

Re: amavis testkeys fail bad RSA signature

There is additional information after checks
If plaintext create  then dkim=pass, but html create dkim=fail. Please help

4

Re: amavis testkeys fail bad RSA signature

Does email in HTML format contain correct DKIM signature (signed by your server)?