Educause Security Discussion mailing list archives

Re: Ironport DKIM


From: Scott Beardsley <scott () CSE UCDAVIS EDU>
Date: Thu, 1 Apr 2010 10:51:16 -0700

We have DKIM (with DNSSEC) running on our mail server (check the
headers!).

Umm... I'm failing to see any DKIM-related headers in it by the time
it passed through the Listserv and arrived at my site?

Ya... looks like the listserv strips them. :(

Here is an example that I sent to gmail (afaict gmail.com does not yet
distinguish between insecure and secure domains):

Received-SPF: pass (google.com: domain of scott () cse ucdavis edu
designates 128.120.246.11 as permitted sender) client-ip=128.120.246.11;
Authentication-Results: mx.google.com; spf=pass (google.com: domain of
scott () cse ucdavis edu designates 128.120.246.11 as permitted sender)
smtp.mail=scott () cse ucdavis edu; dkim=pass header.i=@cse.ucdavis.edu
Received: from webmail.cse.ucdavis.edu (shell.cse.ucdavis.edu
[128.120.246.8])
        (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits))
        (No client certificate requested)
        (Authenticated sender: sbeards () cse ucdavis edu)
        by mail.cse.ucdavis.edu (Postfix) with ESMTPSA id B8DE93DE9B
        for <sc0ttbeardsley () gmail com>; Wed, 31 Mar 2010 16:31:24 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=cse.ucdavis.edu;
        s=mail; t=1270078284;
        bh=Lf0wJWASg7v0rKOVmANUpoZCMXlQsdGTCuXo/TgXzas=;
        h=MIME-Version:Date:From:To:Subject:Message-ID:
         Content-Transfer-Encoding:Content-Type;
        b=WmO06VKAborCfneweGW0Cx/RAJLfyhX6yb7qZRCdIyHvacxMkS18jRvm5GYowq6Am
         XGB+vi3ff38yuIvQOaaK3e41Ng0CBGaz3xy6xzkriJ1V4iIDwvYoaPBt3XcQ84g+GB
         QFTK4vh3xySiRGXkBdTIuCRKZVjnm+H4ca+J6fI4=

Current thread: