[pfx] Re: dual-algo (rsa & ec) dkim signing of pfx-outbound mail -- incorrect receipt @ gmail. pfx, dkimpy or gmail issue?

Edmund Lodewijks via Postfix-users <[email protected]> Mon, 27 Jul 2026 14:22:40 +0200
Newsgroups gmane.mail.postfix.user
Message-ID <[email protected]>

On 2026/07/24 18:31, Viktor Dukhovni via Postfix-users wrote:
> On Thu, Jul 23, 2026 at 03:09:44PM -0400, pgnd via Postfix-users wrote:
> 
>> what's _not_ convincingly clear to me is what *they* do as a result of their ... ahem ... result.
>> randomly drop?  bucket into spam?  nothing?
> 
> In a robust implementation the RSA DKIM signature is sufficient.  I
> don't know whether Google's implementation is robust in that manner.
> 

I sent a test email from my dual-DKIM1-signing mail server to a Gmail 
address, and it works just fine with a DKIM=pass (RSA) and a 
dkim=neutral (no key) for ed25519:

   ARC-Authentication-Results: i=1; mx.google.com; dkim=pass 
[email protected] header.s=20250312 header.b="Z/KBgkd5"; 
dkim=neutral (no key) [email protected] header.s=20260507 
header.b="OOri7m//"; spf=pass (google.com: domain of 
[email protected] designates 49.12.119.27 as permitted sender) 
[email protected]; dmarc=pass (p=NONE sp=NONE 
dis=NONE) header.from=proteamail.com
   Received-SPF: pass (google.com: domain of [email protected] 
designates 49.12.119.27 as permitted sender) client-ip=49.12.119.27;
   Authentication-Results: mx.google.com; dkim=pass 
[email protected] header.s=20250312 header.b="Z/KBgkd5"; 
dkim=neutral (no key) [email protected] header.s=20260507 
header.b="OOri7m//"; spf=pass (google.com: domain of 
[email protected] designates 49.12.119.27 as permitted sender) 
[email protected]; dmarc=pass (p=NONE sp=NONE 
dis=NONE) header.from=proteamail.com
   X-DKIM-Filter: PhoenixDKIM Filter v1.0.0 mail.proteamail.com via 
nbg-mx-proteamail-1 4h7y7s0qfsz31vH
   DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; 
d=proteamail.com; s=20250312; t=1785154169; 
bh=XnsvVURyPHjm4WkMKWl01MSWaid47+fxBfw3ZcFZB2o=; 
h=Message-ID:Date:MIME-Version:To:From:Subject:Content-Type: 
Content-Transfer-Encoding:From:Reply-To:Subject:To:Cc:Date: 
Message-Id:Mime-Version:Content-Type:Content-Transfer-Encoding: 
In-Reply-To:References:Sender:Openpgp:Autocrypt; 
b=Z/KBgkd5d3U9UeUTTmIsTxwKdVYiDM1PqsAR0qIy/Mt4YW1MoGfbEN1If34BK5g3M 
kD5zPrudui2xvfcGmuKO75RDTi40Wud8hFOf2ke5Oi6O3kuZ49PuhlVGdSOlqV9U+T 
kSIkkNghg0e8qtJB8FBwMwTXdNghM2gZ7+3gQbKV9e3yRSTa4xHt3WHz8hwMU0hMWm 
4wwU1oMbKthn/u0tkxxdSdmnBQ6BkwH87N1rgzcZJH0ceMuw9yIiTSCrKnDXMDNVcd 
J8MlhRlYY46StISdQUYD9XZFHSrZoZJylJtnqdGbcpHN7o3vjaCwS4X6EpH4FPLjqY 
fy1DAY3MA+eUw==
   DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; 
d=proteamail.com; s=20260507; t=1785154169; 
bh=XnsvVURyPHjm4WkMKWl01MSWaid47+fxBfw3ZcFZB2o=; 
h=Message-ID:Date:MIME-Version:To:From:Subject:Content-Type: 
Content-Transfer-Encoding:From:Reply-To:Subject:To:Cc:Date: 
Message-Id:Mime-Version:Content-Type:Content-Transfer-Encoding: 
In-Reply-To:References:Sender:Openpgp:Autocrypt; 
b=OOri7m//E+w/IsDwO31D08ZZonf3HsyBJxYrqE7i1msnX47nXn3sSdDJQnUHcURUY 
q83IxOSL94SUqvpvHBLBA==

The whole purpose of dual-signing is to get mail delivered to servers 
that don't deal with ed25519 DKIM signatures. Of course, one can wonder 
why one would dual sign in that case, but that's another discussion.

Kind regards,

     Edmund


-- 
Edmund Lodewijks <[email protected]>
TZ: UTC+2 / GMT+2

_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]