Re: signature verification/signing problem

From: Charles Bartels <cbartels_at_yahoo-inc.com>
Date: Mon, 12 Dec 2011 14:23:03 -0800

On Dec 12, 2011, at 11:44 AM, SM wrote:

> Hi Charles,
> At 08:58 12-12-2011, Charles Bartels wrote:
>> I'm beginning to opendkim sign email for one of my domains and can't
>> figure out where it is going wrong. This current installation is
>> almost identical to one I did earlier that worked fine.
>
> Your message passed DKIM verification.
>
>> The keys appear fine, I tested with "opendkim-testkey"
>> The DNS entry seems fine, as far as I can tell.
>>
>> But emails still fail verification. Below is one of the message I
>> received when I tested
>
> Can you forward the response from autorespond+dkim_at_dk.elandsys.com
>
> Regards,
> -sm
>

Absolutely, here is one of the replies from that:


This is an automatic response. Replies to this message will not generate
an automatic response.
Do not reply to this message except for reporting a problem.

The results are as follows:

DKIM Signature validation: fail
DomainKeys Signature validation: not available
DomainKeys Policy: query failed
DKIM Author Domain Signing Practices: no DNS record for _adsp._domainkey.cctw.yahoo-inc.com

ADSP is not required for DKIM signature validation.

Note: The authentication results are not available as
there was no signature header or the signature could
not be verified
Information about DKIM is available at http://www.elandsys.com/resources/mail/dkim/opendkim.html
Information about ADSP is available at http://www.elandsys.com/resources/sendmail/opendkim.html

Information about dkim-milter is available at http://www.elandsys.com/resources/sendmail/dkim.html


Information about DomainKeys is available at http://www.elandsys.com/resources/sendmail/domainkeys.html


Original message:
Received: from mailtw.cc.tw1.yahoo.com (mailtw.cc.tw1.yahoo.com [119.160.254.62])
        by mx.elandsys.com (8.14.4/8.14.5) with ESMTP id pB6GklCK011878
        (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO)
        for <autorespond+dkim_at_dk.elandsys.com>; Tue, 6 Dec 2011 08:46:54 -0800 (PST)
Authentication-Results: mx.elandsys.com; dkim=fail
        (verification failed; insecure key) header.i=_at_cctw.yahoo-inc.com
        header.b=sKC1Mgae; dkim-adsp=none (insecure policy)
Received: from apacrpt2.cc.corp.tw1.yahoo.com (apacrpt2.cc.corp.tw1.yahoo.com [202.174.4.143])
        by mailtw.cc.tw1.yahoo.com (8.14.4/8.14.4/cctw) with ESMTP id pB6GkeTb049744;
        Tue, 6 Dec 2011 08:46:40 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cctw.yahoo-inc.com;
        s=care; t=1323190001;
        bh=fdkeB/A0FkbVP2k4J4pNPoeWH6vqBm9+b0C3OY87Cw8=;
        h=To:From:Subject:Date:Message-ID;
        b=sKC1MgaeMq8MX2j56+sGxkWZcejFeS3BU+tMr03Id4zL53uXd6RqQz595ZvYutOdt
         crT6MlzR5KB+GzVu6/RlQ==
To: <cbartels_at_yahoo-inc.com>, <cebartels_at_gmail.com>, <cebartels_at_yahoo.com>,
       <autorespond+dkim_at_dk.elandsys.com>
From: cbartels_at_cctw.yahoo-inc.com
Subject: Mail Test2
Date: Wed, 7 Dec 2011 00:46:41 +0800
X-Mailer: Perl script "test_mail.pl"
        using Mail::Sender 0.8.16 by Jenda Krynicky, Czechlands
        running on apacrpt2.cc.corp.tw1.yahoo.com (202.174.4.143)
        under account "cbartels"
Message-ID: <20111206_164641_040920.cbartels_at_cctw.yahoo-inc.com>

Test
Received on Mon Dec 12 2011 - 22:23:33 PST

This archive was generated by hypermail 2.3.0 : Mon Oct 29 2012 - 23:20:22 PST