Files
kumomta/crates/dkim
Wez Furlong 501d1f26e5 dkim: support verifying multiple keys
While auditing Answer::as_txt usage as a follow up from the recent
SPF fix, I noticed a TODO in the dkim code (which we forked from
another implementation) to support processing multiple TXT
records.

This commit implements the necessary tweaks to extract multiple
signatures and attempt to verify them against the incoming message.
2025-03-07 09:26:55 -07:00
..
2024-04-10 13:26:49 -07:00
2024-04-10 13:26:49 -07:00
2025-03-07 09:26:55 -07:00
2023-06-15 09:10:39 -07:00
2023-06-15 09:10:39 -07:00
2023-06-15 09:10:39 -07:00
2023-06-15 09:10:39 -07:00
2023-08-25 08:55:30 -07:00

kumo-dkim

DKIM (RFC6376) implementation

Features

Verifying email signatures

Example:

let res: DKIMResult = kumo_dkim::verify_email(&from_domain, &parsed_email).await?;

if let Some(err) = &res.error() {
  error!(logger, "dkim verify fail: {}", err);
}

println!("dkim={}", res.with_detail());

Signing an email

Example:

let private_key =
    rsa::RsaPrivateKey::read_pkcs1_pem_file(Path::new("./test/keys/2022.private"))?;

let signer = SignerBuilder::new()
    .with_signed_headers(["From", "Subject"])?
    .with_private_key(private_key)
    .with_selector("2020")
    .with_signing_domain("example.com")
    .build()?;
let signature = signer.sign(&email)?;

println!("{}", signature); // DKIM-Signature: ...

See the SignerBuilder object documentation for more information.

Generate a test DKIM key

Using OpenDKIM:

opendkim-genkey \
    --testmode \
    --domain=example.com \
    --selector=2022 \
    --nosubdomains