1

Topic: DKIM not signing / missing / from outlook, but works from SOGo

==== REQUIRED BASIC INFO OF YOUR IREDMAIL SERVER ====
- iRedMail version (check /etc/iredmail-release): 0.9.8 OPENLDAP edition.
- Linux/BSD distribution name and version: UBUNTU Server 18.04
- Store mail accounts in which backend (LDAP/MySQL/PGSQL): LDAP
- Web server (Apache or Nginx): Nginx
- Manage mail accounts with iRedAdmin-Pro? No
- [IMPORTANT] Related original log or error message is required if you're experiencing an issue.
====

I'm using DKIM Validator and other online tools to double check.

- When I send the email from SOGo web client, it gets signed by DKIM just find, and get validated
- If I send it via Outlook (and yes, I'm using port 587), it doesn't get signed

Please help

----

Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.

2

Re: DKIM not signing / missing / from outlook, but works from SOGo

Ok, so I did a little digging, and found this article:

https://lists.amavis.org/pipermail/amav … 04428.html

That helped, but now I have a new problem:

From DKIM Validator:
Points breakdown:
0.1 DKIM_SIGNED            Message has a DKIM or DK signature, not necessarily valid
0.0 T_DKIM_INVALID         DKIM-Signature header exists but is not valid

From SparkPost Tools:
Signature could not be verified.


How can I make sure that my DKIM-Signature header is valid?
This will create a lot of SPAM / JUNK mail issues.

3

Re: DKIM not signing / missing / from outlook, but works from SOGo

So how do I get support here?

4

Re: DKIM not signing / missing / from outlook, but works from SOGo

Do you have valid DNS record for DKIM?
Run "amavisd-new testkeys" on your server to test it first.

5

Re: DKIM not signing / missing / from outlook, but works from SOGo

ZhangHuangbin wrote:

Do you have valid DNS record for DKIM?
Run "amavisd-new testkeys" on your server to test it first.

Yes, I do.. here is what I get:

root@iredmail:/# amavisd-new testkeys
TESTING#1 mailjockey.com: dkim._domainkey.mailjockey.com => pass

6

Re: DKIM not signing / missing / from outlook, but works from SOGo

It is the signature verification which is failing miserably at all sites.

7

Re: DKIM not signing / missing / from outlook, but works from SOGo

Then it means your DKIM key and DNS record are ok. Try to send email to Gmail and check the mail headers, Gmail will store the DKIM verification result in mail header.

8

Re: DKIM not signing / missing / from outlook, but works from SOGo

Looks like it is passing on gmail tools.
But failing and going to spam, when I send test to Office 365 email address OR to DKIM validator.

============================================================================
This is SPF/DKIM/DMARC/RBL report generated by a test tool provided
    by AdminSystem Software Limited.

Any problem, please contact support@emailarchitect.net
============================================================================
Report-Id: 62acc1f1
Sender: peter.parker@mailjockey.com
Source-IP: 45.32.92.78
Validator-Version: 1.05
============================================================================
Original email header:

x-sender: peter.parker@mailjockey.com
x-receiver: test-62acc1f1@appmaildev.com
Received: from red.mailjockey.com ([45.32.92.78]) by appmaildev.com with Microsoft SMTPSVC(8.5.9600.16384);
     Wed, 27 Jun 2018 18:07:10 +0000
Received: from red.mailjockey.com (red.mailjockey.com [127.0.0.1])
    by red.mailjockey.com (Postfix) with ESMTP id 68DA7F9A0743
    for <test-62acc1f1@appmaildev.com>; Wed, 27 Jun 2018 18:07:09 +0000 (UTC)
Authentication-Results: red.mailjockey.com (amavisd-new);
    dkim=pass (1024-bit key) reason="pass (just generated, assumed good)"
    header.d=mailjockey.com
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=mailjockey.com;
     h=x-mailer:to:date:date:message-id:subject:subject:mime-version
    :content-transfer-encoding:content-type:content-type:from:from;
     s=dkim; t=1530122829; x=1532714830; bh=JHuPF1yLj7ZOSLwgHtNJNDfn
    BGLW0IaotOwLZrIecpA=; b=Z7QbcyH2Cw4Q5O/zn53hCNLF6XqyXdm7eerQoF3F
    CXQzE5ltECjwBIB/8KI1r8LwV0r6YhnO4CBTlkZfDTHCG7q0F8D+ZIfv6XClyZPm
    8M9axOtv5eUVlx+4WPgwhqKS8XhovNtFDjHGGfXZscEnPtx6Xf/L5j9UFx56WJBj
    ROQ=
X-Virus-Scanned: Debian amavisd-new at red.mailjockey.com
Received: from red.mailjockey.com ([127.0.0.1])
    by red.mailjockey.com (red.mailjockey.com [127.0.0.1]) (amavisd-new, port 10026)
    with ESMTP id NYqFj2cLHvdt for <test-62acc1f1@appmaildev.com>;
    Wed, 27 Jun 2018 18:07:09 +0000 (UTC)
Received: from [192.168.77.52] (_gateway [192.168.77.1])
    by red.mailjockey.com (Postfix) with ESMTPSA id 11625F9A07ED
    for <test-62acc1f1@appmaildev.com>; Wed, 27 Jun 2018 18:07:09 +0000 (UTC)
From: Peter Parker <peter.parker@mailjockey.com>
Content-Type: text/plain;
    charset=us-ascii
Content-Transfer-Encoding: 7bit
Mime-Version: 1.0 (Mac OS X Mail 11.4 \(3445.8.2\))
Subject: Please test my DKIM
Message-Id: <01D7FAF3-D798-40F0-84D9-1A78396651EE@mailjockey.com>
Date: Wed, 27 Jun 2018 11:07:08 -0700
To: test-62acc1f1@appmaildev.com
X-Mailer: Apple Mail (2.3445.8.2)
Return-Path: peter.parker@mailjockey.com
X-OriginalArrivalTime: 27 Jun 2018 18:07:11.0184 (UTC) FILETIME=[AB660500:01D40E41]

============================================================================
SPF: Pass
============================================================================

SPF-Record: v=spf1 mx ~all
Sender-IP:45.32.92.78
Sender-Domain:mailjockey.com

Query TEXT record from DNS server for: mailjockey.com
[TXT]: v=spf1 mx ~all
Parsing SPF record: v=spf1 mx ~all

Mechanisms: v=spf1

Mechanisms: mx
Testing mechanism mx
Query MX record from DNS server for: mailjockey.com
[MX]: red.mailjockey.com
Testing mechanism A:red.mailjockey.com/128
Query A record from DNS server for: red.mailjockey.com
[A]: 45.32.92.78
Testing CIDR: source=45.32.92.78;  45.32.92.78/128
mx hit, Qualifier: +

============================================================================
DKIM: pass
============================================================================

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=mailjockey.com;
     h=x-mailer:to:date:date:message-id:subject:subject:mime-version
    :content-transfer-encoding:content-type:content-type:from:from;
     s=dkim; t=1530122829; x=1532714830; bh=JHuPF1yLj7ZOSLwgHtNJNDfn
    BGLW0IaotOwLZrIecpA=; b=Z7QbcyH2Cw4Q5O/zn53hCNLF6XqyXdm7eerQoF3F
    CXQzE5ltECjwBIB/8KI1r8LwV0r6YhnO4CBTlkZfDTHCG7q0F8D+ZIfv6XClyZPm
    8M9axOtv5eUVlx+4WPgwhqKS8XhovNtFDjHGGfXZscEnPtx6Xf/L5j9UFx56WJBj
    ROQ=
Signed-by: peter.parker@mailjockey.com
Expected-Body-Hash: JHuPF1yLj7ZOSLwgHtNJNDfnBGLW0IaotOwLZrIecpA=
Public-Key: v=DKIM1; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCv6BEKi888uYCLnOy9X7X+rKNNpIweU/NBTKo97WMYnLuHLXvkuawtzuHUUc7Trb6xbpEgiFiQBrmbVB0ywM6gfaO1EN44R4TU2e4RKfIg4rFo9qC99lYzHNORMWkWoyK8cvr/h7eqmzq+QVNCSAIS/2R9BKHfPapvEwoiKunp6wIDAQAB;

DKIM-Result: pass

============================================================================
DMARC: pass
============================================================================

_dmarc.mailjockey.com: v=DMARC1; p=none
Received-SPF: pass (appmaildev.com: domain of peter.parker@mailjockey.com designates 45.32.92.78 as permitted sender) client-ip=45.32.92.78
Authentication-Results: appmaildev.com;
    dkim=pass header.d=mailjockey.com;
    spf=pass (appmaildev.com: domain of peter.parker@mailjockey.com designates 45.32.92.78 as permitted sender) client-ip=45.32.92.78;
    dmarc=pass (adkim=r aspf=r p=none) header.from=mailjockey.com;

============================================================================
DomainKey: none
============================================================================

DomainKey-Result: none (no signature)
If DKIM result is passed, you can ignore DomainKey result: none

============================================================================
PTR: ExistsRecord
============================================================================

Sender-IP: 45.32.92.78
Query 78.92.32.45.in-addr.arpa
Host: red.mailjockey.com

============================================================================
RBL: NotListed
============================================================================

bl.spamcop.net:Not Listed (OK) - http://bl.spamcop.net
cbl.abuseat.org:Not Listed (OK) - http://cbl.abuseat.org
b.barracudacentral.org:Not Listed (OK) - http://www.barracudacentral.org/rbl/removal-request
dnsbl.sorbs.net:Not Listed (OK) - http://www.sorbs.net
http.dnsbl.sorbs.net:Not Listed (OK) - http://www.sorbs.net
dul.dnsbl.sorbs.net:Not Listed (OK) - http://www.sorbs.net
misc.dnsbl.sorbs.net:Not Listed (OK) - http://www.sorbs.net
smtp.dnsbl.sorbs.net:Not Listed (OK) - http://www.sorbs.net
socks.dnsbl.sorbs.net:Not Listed (OK) - http://www.sorbs.net
spam.dnsbl.sorbs.net:Not Listed (OK) - http://www.sorbs.net
web.dnsbl.sorbs.net:Not Listed (OK) - http://www.sorbs.net
zombie.dnsbl.sorbs.net:Not Listed (OK) - http://www.sorbs.net
pbl.spamhaus.org:Not Listed (OK) - http://www.spamhaus.org/pbl/
sbl.spamhaus.org:Not Listed (OK) - http://www.spamhaus.org/sbl/
xbl.spamhaus.org:Not Listed (OK) - http://www.spamhaus.org/xbl/
zen.spamhaus.org:Not Listed (OK) - http://www.spamhaus.org/zen/
ubl.unsubscore.com:Not Listed (OK) - http://www.lashback.com/blacklist/
rbl.spamlab.com:Not Listed (OK) - http://tools.appriver.com/index.aspx?tool=rbl
dyna.spamrats.com:Not Listed (OK) - http://www.spamrats.com
noptr.spamrats.com:Not Listed (OK) - http://www.spamrats.com
spam.spamrats.com:Not Listed (OK) - http://www.spamrats.com
cbl.anti-spam.org.cn:Not Listed (OK) - http://www.anti-spam.org.cn/?Locale=en_US
cdl.anti-spam.org.cn:Not Listed (OK) - http://www.anti-spam.org.cn/?Locale=en_US
dnsbl.inps.de:Not Listed (OK) - http://dnsbl.inps.de/index.cgi?lang=en
drone.abuse.ch:Not Listed (OK) - http://dnsbl.abuse.ch
httpbl.abuse.ch:Not Listed (OK) - http://dnsbl.abuse.ch
korea.services.net:Not Listed (OK) - http://korea.services.net
spamrbl.imp.ch:Not Listed (OK) - http://antispam.imp.ch
wormrbl.imp.ch:Not Listed (OK) - http://antispam.imp.ch
virbl.bit.nl:Not Listed (OK) - http://virbl.bit.nl    
rbl.suresupport.com:Not Listed (OK) - http://suresupport.com/postmaster
dsn.rfc-ignorant.org:Not Listed (OK) - http://www.rfc-ignorant.org/policy-dsn.php
spamguard.leadmon.net:Not Listed (OK) - http://www.leadmon.net/SpamGuard/
dnsbl.tornevall.org:Not Listed (OK) - http://opm.tornevall.org
netblock.pedantic.org:Not Listed (OK) - http://pedantic.org
multi.surbl.org:Not Listed (OK) - http://www.surbl.org
ix.dnsbl.manitu.net:Not Listed (OK) - http://www.dnsbl.manitu.net
tor.dan.me.uk:Not Listed (OK) - http://www.dan.me.uk/dnsbl
rbl.efnetrbl.org:Not Listed (OK) - http://rbl.efnetrbl.org
dnsbl.dronebl.org:Not Listed (OK) - http://www.dronebl.org
access.redhawk.org:Not Listed (OK) - http://www.redhawk.org/index.php?option … ;Itemid=33
db.wpbl.info:Not Listed (OK) - http://www.wpbl.info
rbl.interserver.net:Not Listed (OK) - http://rbl.interserver.net
query.senderbase.org:Not Listed (OK) - http://www.senderbase.org/about
bogons.cymru.com:Not Listed (OK) - http://www.team-cymru.org/Services/Bogons/
csi.cloudmark.com:Not Listed (OK) - http://www.cloudmark.com/en/products/cl … ence/index

short.rbl.jp:DnsTimeout - http://www.rbl.jp
virus.rbl.jp:DnsTimeout - http://www.rbl.jp


============================================================================
Original message source
============================================================================
x-sender: peter.parker@mailjockey.com
x-receiver: test-62acc1f1@appmaildev.com
Received: from red.mailjockey.com ([45.32.92.78]) by appmaildev.com with Microsoft SMTPSVC(8.5.9600.16384);
     Wed, 27 Jun 2018 18:07:10 +0000
Received: from red.mailjockey.com (red.mailjockey.com [127.0.0.1])
    by red.mailjockey.com (Postfix) with ESMTP id 68DA7F9A0743
    for <test-62acc1f1@appmaildev.com>; Wed, 27 Jun 2018 18:07:09 +0000 (UTC)
Authentication-Results: red.mailjockey.com (amavisd-new);
    dkim=pass (1024-bit key) reason="pass (just generated, assumed good)"
    header.d=mailjockey.com
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=mailjockey.com;
     h=x-mailer:to:date:date:message-id:subject:subject:mime-version
    :content-transfer-encoding:content-type:content-type:from:from;
     s=dkim; t=1530122829; x=1532714830; bh=JHuPF1yLj7ZOSLwgHtNJNDfn
    BGLW0IaotOwLZrIecpA=; b=Z7QbcyH2Cw4Q5O/zn53hCNLF6XqyXdm7eerQoF3F
    CXQzE5ltECjwBIB/8KI1r8LwV0r6YhnO4CBTlkZfDTHCG7q0F8D+ZIfv6XClyZPm
    8M9axOtv5eUVlx+4WPgwhqKS8XhovNtFDjHGGfXZscEnPtx6Xf/L5j9UFx56WJBj
    ROQ=
X-Virus-Scanned: Debian amavisd-new at red.mailjockey.com
Received: from red.mailjockey.com ([127.0.0.1])
    by red.mailjockey.com (red.mailjockey.com [127.0.0.1]) (amavisd-new, port 10026)
    with ESMTP id NYqFj2cLHvdt for <test-62acc1f1@appmaildev.com>;
    Wed, 27 Jun 2018 18:07:09 +0000 (UTC)
Received: from [192.168.77.52] (_gateway [192.168.77.1])
    by red.mailjockey.com (Postfix) with ESMTPSA id 11625F9A07ED
    for <test-62acc1f1@appmaildev.com>; Wed, 27 Jun 2018 18:07:09 +0000 (UTC)
From: Peter Parker <peter.parker@mailjockey.com>
Content-Type: text/plain;
    charset=us-ascii
Content-Transfer-Encoding: 7bit
Mime-Version: 1.0 (Mac OS X Mail 11.4 \(3445.8.2\))
Subject: Please test my DKIM
Message-Id: <01D7FAF3-D798-40F0-84D9-1A78396651EE@mailjockey.com>
Date: Wed, 27 Jun 2018 11:07:08 -0700
To: test-62acc1f1@appmaildev.com
X-Mailer: Apple Mail (2.3445.8.2)
Return-Path: peter.parker@mailjockey.com
X-OriginalArrivalTime: 27 Jun 2018 18:07:11.0184 (UTC) FILETIME=[AB660500:01D40E41]

Can you please look at my DKIM. Is it working.

Thank you,
Peter Parker
============================================================================

9

Re: DKIM not signing / missing / from outlook, but works from SOGo

Hi Zhang,

Still having issues sad ... I sent two emails to two of my colleagues at gmail and two to two of my colleagues at office 365.
It all ended up in Junk / Spam.

Not sure what's going on.

10 (edited by RikuS 2018-07-03 05:01:48)

Re: DKIM not signing / missing / from outlook, but works from SOGo

Based on that report, there's no errors and everything works fine. Large email providers have their own policies about spam and often you need to earn reputation to have them fully trust your server/IP.

But also your IP is blacklisted by SORBS and Reverse PTR record is invalid.