Skip to content

DKIM does not actually work #117

@prj

Description

@prj

Following the tutorial it is impossible to set up DKIM.
It works only as long as you let it re-generate it every time, which makes it completely useless, as all e-mails fail DKIM unless you update your domain every single time you restart the server!

The moment you try to send something via SMTP, you get the following error:
mail-forwarder | Dec 11 14:06:08 56cddd08332c opendkim[953]: default._domainkey.xxxx.com' key data is not secure:
mail-forwarder | Dec 11 14:06:08 56cddd08332c opendkim[953]: 5339536064D: error loading key 'default._domainkey.xxxx.com'

I can only surmise that this happens when you are mounting the volume on the host, that some permissions do not match.
If I just let it as-is, then I get this error, if I try to constrain the users, then I get a permission denied error.

In my case the toplevel is owned by root, txt owned by root, key owned by "systemd-network:systemd-journal".
Permissions are 0600 on the files.

Not only does this break DKIM, it is impossible to send any e-mail at all, it errors out on the the first e-mail and then just times out.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions