邮件服务器-邮件系统-邮件技术论坛(BBS)

标题: dkim处理设定?? [打印本页]

作者: luke999    时间: 2010-2-19 09:32
标题: dkim处理设定??
小弟我於mdaemon设定了dkim

按照mdaemon knowledge设定dkim於dns server

然後dns server与dns client服务重新启动

但寄信到gmail.看该信件原始档案~得到其中一行为:
Authentication-Results: mx.google.com; spf=pass (google.com: domain of [email=prvs=16663f4093=ttt@abc.com]prvs=16663f4093=ttt@abc.com[/email] designates 1.2.3.4 as permitted sender) [email=smtp.mail=prvs=16663f4093=abc.com]smtp.mail=prvs=16663f4093=ttt@abc.com[/email]; dkim=neutral (no key) [email=header.i=@abc.com]header.i=@abc.com[/email]
为何还说没有dkim呢?
谢谢~
作者: Kyan    时间: 2010-2-19 19:53
原帖由 luke999 於 2010-2-19 09:32 發表
小弟我於mdaemon設定了dkim

按照mdaemon knowledge設定dkim於dns server

然後dns server與dns client服務重新啟動

但寄信到gmail.看該信件原始檔案~得到其中一行為:
Authentication-Results: mx.googl ...




MDaemon supports both Sender Policy Framework (SPF) and Sender ID Framework (SIDF) to help verify sending servers and protect against spoofing and phishing, which are two common types of email forgery in which the sender of the message attempts to make the message appear to be coming from someone else.

Many domains publish MX records in the Domain Name System (DNS) to identify the locations permitted to receive mail for them, but this doesn't identify the locations allowed to send mail for them. SPF is a means whereby domains can also publish sender records to identify those locations authorized to send messages. By performing an SPF lookup on incoming messages, MDaemon can attempt to determine whether or not the sending server is permitted to deliver mail for the purported sending domain, and consequently determine whether or not the sender's address may have been forged or "spoofed". Sender ID is related to SPF, but it is more complex in order to more reliably determine the actual domain purported to have sent the message, and to reduce the likelihood of incorrect results.

Use the options on this tab to configure your server's SPF and Sender ID settings.

For more information on SPF, visit:

http://spf.pobox.com

For more information on Sender ID, visit:

http://www.microsoft.com/mscorp/safety/technologies/senderid/default.mspx


------



Use this screen to configure MDaemon to verify DomainKeys Identified Mail (DKIM) and/or DomainKeys (DK) signatures in incoming remote messages. When this feature is enabled and an incoming message has been cryptographically signed, MDaemon will retrieve the public key from the DNS record of the domain taken from the signature and then use that key to test the message’s DKIM  or DK signature to determine its validity.

If the signature passes the verification test, the message will continue on to the next step in the regular delivery process. Additionally, if the domain taken from the signature also appears on the Approved List, the message’s Spam Filter score will receive a beneficial adjustment.

If a message has no signature, or if the signature is invalid, MDaemon will retrieve the Author Domain Signing Practices (ADSP) record of the domain in the From header to determine whether or not all of that domain’s messages should be signed. If the ADSP record indicates that a valid signature is required and the public key indicates that the signer is not merely testing DKIM, the message will receive a "Fail" result and be treated accordingly—it can be rejected outright or accepted but have its Spam Filter score adjusted upward.

Finally, if a site's ADSP record uses a syntax unknown to MDaemon, if no record exists at all, or if the ADSP option located on the DKIM Options screen is disabled, then no punitive measures will be taken. The unsigned or invalidly signed message will be treated as if the domain signs only some of its messages.

For more on DKIM see: http://www.dkim.org/

作者: luke999    时间: 2010-2-19 21:26
原帖由 Kyan 于 2010-2-19 19:53 发表


9087

MDaemon supports both Sender Policy Framework (SPF) and Sender ID Framework (SIDF) to help verify sending servers and protect against spoofing and phishing, which are two common types of e ...


大哥~你似乎只介绍SPF与DK内容
这我知道~也查过了


首先
那信件的内容是我寄送到gmail的原始档部分内容
你第一个画面为本邮件伺服器检查来信的信件spf
这不是我现在的问题

我现在的问题~在於本邮件伺服器寄送信件到gmail
(1)
spf~gmail检查问题~由於本机器有几个固定IP在跑~所以可能会跑来跑去~
所以(1)是另外一个帖子问题
http://www.5dmail.net/bbs/thread-187699-1-1.html

(2)
现在是我邮件伺服器寄件到Gmail
从gmail收件者~检视该信件原始档~重点部分内容有:

该如何正确在mdaemon设定
dkim=neutral (no key)


但重点是在mdaemon如何正确的设定
麻烦一步步的指导~谢谢

[ 本帖最后由 luke999 于 2010-2-19 21:41 编辑 ]
作者: alextawang    时间: 2010-12-24 16:18
今天也碰到这个问题了,对方发过来的邮件,通过不了我的DKIM验证,被当作垃圾邮件处理了。会不会国内很多邮件发出来跟本就没有做DKIM的签名之类的,所以过不了DKIM验证?是不是该将DKIM验证先暂时取消掉?
作者: tdk    时间: 2010-12-24 23:05
dkim 邮件服务器上的密钥确认生成并保存了?
dns 上的 dkim 密钥确认格式正确?
这两个是一对儿, 都不能少,也不能错
作者: tongxin365    时间: 2010-12-30 18:39
标题: 请教hyacinth㊣
dkim 邮件服务器上的密钥确认生成并保存了?
dns 上的 dkim 密钥确认格式正确?
这两个是一对儿, 都不能少,也不能错
请问你说的这2个具体的操作时该怎么操作,要点哪个菜单来设置,和具体的操作方法请说,谢谢
作者: tdk    时间: 2010-12-30 20:53
标题: 回复 6楼 tongxin365 的帖子
不用md,所以不清楚具体设置位置
你截图你设置的看看




欢迎光临 邮件服务器-邮件系统-邮件技术论坛(BBS) (http://bbs.5dmail.cn/) Powered by Discuz! X3.2