[pfx] Re: New to Postfix, Google problems

Matus UHLAR - fantomas via Postfix-users <[email protected]>
Newsgroups gmane.mail.postfix.user
Message-ID <[email protected]>
>On Fri, Aug 7, 2026, at 12:23 PM, Jaroslaw Rafa via Postfix-users wrote:
>> The certificates only come into play when you are the RECEIVING side.If you
>> are SENDING mail, no certificates are involved on your side, at all.
>>
>> So trouble with SENDING mail to another server cannot be cause dby
>> certificates.

On 07.08.26 12:40, Paul Tomblin via Postfix-users wrote:
> I believe you’re wrong about that.  If you sign your email with a 
> self-signed certificate, then Google has to trust that certificate in 
> order for them to verify your signature.  If they decide not to accept 
> your self-signed certificate, then they mark your email as a DKIM failure.

I guess you mistook DKIM and SSL certificates.

DKIM is one story, but DKIM public keys are published in DNS so Google or 
other recipients can verify the signature against it.  
Sender domain can be protested by DNSSEC, in which case it's pretty safe to 
veriy.

Signing e-mail itself (S/MIME or PGP) is different story, usually taken care 
of by MUAs, not MTAs.

Using certificate for SSL/TLS client client is also another story
- as previously noted, Let's Encrypt certificates are only for servers, thus 
not usable for client connections or S/MIME.

-- 
Matus UHLAR - fantomas, [email protected] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
Spam = (S)tupid (P)eople's (A)dvertising (M)ethod
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.