[pfx] Re: dual-algo (rsa & ec) dkim signing of pfx-outbound mail -- incorrect receipt @ gmail. pfx, dkimpy or gmail issue?
Edmund Lodewijks via Postfix-users <[email protected]> Mon, 27 Jul 2026 14:22:40 +0200
| Newsgroups | gmane.mail.postfix.user |
|---|---|
| Message-ID | <[email protected]> |
On 2026/07/24 18:31, Viktor Dukhovni via Postfix-users wrote: > On Thu, Jul 23, 2026 at 03:09:44PM -0400, pgnd via Postfix-users wrote: > >> what's _not_ convincingly clear to me is what *they* do as a result of their ... ahem ... result. >> randomly drop? bucket into spam? nothing? > > In a robust implementation the RSA DKIM signature is sufficient. I > don't know whether Google's implementation is robust in that manner. > I sent a test email from my dual-DKIM1-signing mail server to a Gmail address, and it works just fine with a DKIM=pass (RSA) and a dkim=neutral (no key) for ed25519: ARC-Authentication-Results: i=1; mx.google.com; dkim=pass [email protected] header.s=20250312 header.b="Z/KBgkd5"; dkim=neutral (no key) [email protected] header.s=20260507 header.b="OOri7m//"; spf=pass (google.com: domain of [email protected] designates 49.12.119.27 as permitted sender) [email protected]; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=proteamail.com Received-SPF: pass (google.com: domain of [email protected] designates 49.12.119.27 as permitted sender) client-ip=49.12.119.27; Authentication-Results: mx.google.com; dkim=pass [email protected] header.s=20250312 header.b="Z/KBgkd5"; dkim=neutral (no key) [email protected] header.s=20260507 header.b="OOri7m//"; spf=pass (google.com: domain of [email protected] designates 49.12.119.27 as permitted sender) [email protected]; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=proteamail.com X-DKIM-Filter: PhoenixDKIM Filter v1.0.0 mail.proteamail.com via nbg-mx-proteamail-1 4h7y7s0qfsz31vH DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=proteamail.com; s=20250312; t=1785154169; bh=XnsvVURyPHjm4WkMKWl01MSWaid47+fxBfw3ZcFZB2o=; h=Message-ID:Date:MIME-Version:To:From:Subject:Content-Type: Content-Transfer-Encoding:From:Reply-To:Subject:To:Cc:Date: Message-Id:Mime-Version:Content-Type:Content-Transfer-Encoding: In-Reply-To:References:Sender:Openpgp:Autocrypt; b=Z/KBgkd5d3U9UeUTTmIsTxwKdVYiDM1PqsAR0qIy/Mt4YW1MoGfbEN1If34BK5g3M kD5zPrudui2xvfcGmuKO75RDTi40Wud8hFOf2ke5Oi6O3kuZ49PuhlVGdSOlqV9U+T kSIkkNghg0e8qtJB8FBwMwTXdNghM2gZ7+3gQbKV9e3yRSTa4xHt3WHz8hwMU0hMWm 4wwU1oMbKthn/u0tkxxdSdmnBQ6BkwH87N1rgzcZJH0ceMuw9yIiTSCrKnDXMDNVcd J8MlhRlYY46StISdQUYD9XZFHSrZoZJylJtnqdGbcpHN7o3vjaCwS4X6EpH4FPLjqY fy1DAY3MA+eUw== DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=proteamail.com; s=20260507; t=1785154169; bh=XnsvVURyPHjm4WkMKWl01MSWaid47+fxBfw3ZcFZB2o=; h=Message-ID:Date:MIME-Version:To:From:Subject:Content-Type: Content-Transfer-Encoding:From:Reply-To:Subject:To:Cc:Date: Message-Id:Mime-Version:Content-Type:Content-Transfer-Encoding: In-Reply-To:References:Sender:Openpgp:Autocrypt; b=OOri7m//E+w/IsDwO31D08ZZonf3HsyBJxYrqE7i1msnX47nXn3sSdDJQnUHcURUY q83IxOSL94SUqvpvHBLBA== The whole purpose of dual-signing is to get mail delivered to servers that don't deal with ed25519 DKIM signatures. Of course, one can wonder why one would dual sign in that case, but that's another discussion. Kind regards, Edmund -- Edmund Lodewijks <[email protected]> TZ: UTC+2 / GMT+2 _______________________________________________ Postfix-users mailing list -- [email protected] To unsubscribe send an email to [email protected]