6.0.0-alpha14
7/2/25

[#13877] Add Support for DKIM Validation
Summary Add Support for DKIM Validation
Queue IMP
Queue Version 6.2.7
Type Enhancement
State Rejected
Priority 1. Low
Owners
Requester sascha (at) valckenier-kips (dot) de
Created 02/22/2015 (3783 days ago)
Due
Updated 03/18/2015 (3759 days ago)
Assigned
Resolved 03/04/2015 (3773 days ago)
Milestone
Patch No

History
03/18/2015 11:39:23 AM arjen+horde (at) de-korte (dot) org Comment #6 Reply to this comment
What i mean is, verfication of the DKIM Information from Mails and
Display if the DKIM are okay, has a problem like (Bad Signig Date,
Bad Checksum) or has no DKIM Signig.
If messages have bad DKIM signatures, they should NOT be reaching 
the user.  That's the whole purpose of DKIM.
While I agree that showing the DKIM information to end-users is 
probably a bad idea, messages with broken DKIM signatures should never 
be outright rejected (not shown). The purpose of DKIM is to see 
whether or not a message has been 'tampered' with.

Only if a sender has stated in a _dmarc.domain record that messages 
should be rejected if failing to authenticate, not showing the message 
to an end-user may be an option. But currently there are so many 
systems (including the Horde mailinglist server) that break DKIM 
signatures, that it is insane to do so based on a broken DKIM 
signature alone.
03/18/2015 11:06:21 AM marco (at) csita (dot) unige (dot) it Comment #5 Reply to this comment
GMail has that feature and shows to the user a feedback in case of 
valid signature.
Will be in the future, if all the services will implement DKIM 
correctly, unsigned/unverified mails could be dropped before reaching 
the user, but not for now.
03/04/2015 05:51:29 AM Michael Slusarz Comment #4
State ⇒ Rejected
Reply to this comment
What i mean is, verfication of the DKIM Information from Mails and 
Display if the DKIM are okay, has a problem like (Bad Signig Date, 
Bad Checksum) or has no DKIM Signig.
If messages have bad DKIM signatures, they should NOT be reaching the 
user.  That's the whole purpose of DKIM.
02/24/2015 08:06:49 AM sascha (at) valckenier-kips (dot) de Comment #3 Reply to this comment
What i mean is, verfication of the DKIM Information from Mails and 
Display if the DKIM are okay, has a problem like (Bad Signig Date, Bad 
Checksum) or has no DKIM Signig.

You can see, what i mean in Thunderbird with Addon "DKIM Validator"

02/23/2015 10:37:33 PM Michael Slusarz Comment #2 Reply to this comment
DKIM is *not* designed to be user displayable information.  it is an 
authentication/transport level security setting and should be handled 
by automatic means.

Requiring a user to visually parse a message and/or the DKIM status 
sort of defeats the whole purpose of DKIM in the first place.
02/22/2015 01:28:36 AM sascha (at) valckenier-kips (dot) de Comment #1
Priority ⇒ 1. Low
Type ⇒ Enhancement
Summary ⇒ Add Support for DKIM Validation
Queue ⇒ IMP
Milestone ⇒
Patch ⇒ No
State ⇒ New
Reply to this comment
Please add DKIM Validator in the frame of the Mail, with state, NO 
DKIM, Good, Warning and BAD.

Also a option where any rules can be setup, like no warning, or show 
or not, if DKIM is in mail. Additional Black and Whitelist, based on 
DKIM IDs.
Black/Whitelist on Userlevel and Systemlevel

Thanks

Saved Queries