On 2026/07/24 18:31, Viktor Dukhovni via Postfix-users wrote:
On Thu, Jul 23, 2026 at 03:09:44PM -0400, pgnd via Postfix-users wrote:
what's _not_ convincingly clear to me is what *they* do as a result of their
... ahem ... result.
randomly drop? bucket into spam? nothing?
In a robust implementation the RSA DKIM signature is sufficient. I
don't know whether Google's implementation is robust in that manner.
I sent a test email from my dual-DKIM1-signing mail server to a Gmail
address, and it works just fine with a DKIM=pass (RSA) and a
dkim=neutral (no key) for ed25519:
ARC-Authentication-Results: i=1; mx.google.com; dkim=pass
[email protected] header.s=20250312 header.b="Z/KBgkd5";
dkim=neutral (no key) [email protected] header.s=20260507
header.b="OOri7m//"; spf=pass (google.com: domain of
[email protected] designates 49.12.119.27 as permitted sender)
[email protected]; dmarc=pass (p=NONE sp=NONE
dis=NONE) header.from=proteamail.com
Received-SPF: pass (google.com: domain of [email protected]
designates 49.12.119.27 as permitted sender) client-ip=49.12.119.27;
Authentication-Results: mx.google.com; dkim=pass
[email protected] header.s=20250312 header.b="Z/KBgkd5";
dkim=neutral (no key) [email protected] header.s=20260507
header.b="OOri7m//"; spf=pass (google.com: domain of
[email protected] designates 49.12.119.27 as permitted sender)
[email protected]; dmarc=pass (p=NONE sp=NONE
dis=NONE) header.from=proteamail.com
X-DKIM-Filter: PhoenixDKIM Filter v1.0.0 mail.proteamail.com via
nbg-mx-proteamail-1 4h7y7s0qfsz31vH
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=proteamail.com; s=20250312; t=1785154169;
bh=XnsvVURyPHjm4WkMKWl01MSWaid47+fxBfw3ZcFZB2o=;
h=Message-ID:Date:MIME-Version:To:From:Subject:Content-Type:
Content-Transfer-Encoding:From:Reply-To:Subject:To:Cc:Date:
Message-Id:Mime-Version:Content-Type:Content-Transfer-Encoding:
In-Reply-To:References:Sender:Openpgp:Autocrypt;
b=Z/KBgkd5d3U9UeUTTmIsTxwKdVYiDM1PqsAR0qIy/Mt4YW1MoGfbEN1If34BK5g3M
kD5zPrudui2xvfcGmuKO75RDTi40Wud8hFOf2ke5Oi6O3kuZ49PuhlVGdSOlqV9U+T
kSIkkNghg0e8qtJB8FBwMwTXdNghM2gZ7+3gQbKV9e3yRSTa4xHt3WHz8hwMU0hMWm
4wwU1oMbKthn/u0tkxxdSdmnBQ6BkwH87N1rgzcZJH0ceMuw9yIiTSCrKnDXMDNVcd
J8MlhRlYY46StISdQUYD9XZFHSrZoZJylJtnqdGbcpHN7o3vjaCwS4X6EpH4FPLjqY
fy1DAY3MA+eUw==
DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed;
d=proteamail.com; s=20260507; t=1785154169;
bh=XnsvVURyPHjm4WkMKWl01MSWaid47+fxBfw3ZcFZB2o=;
h=Message-ID:Date:MIME-Version:To:From:Subject:Content-Type:
Content-Transfer-Encoding:From:Reply-To:Subject:To:Cc:Date:
Message-Id:Mime-Version:Content-Type:Content-Transfer-Encoding:
In-Reply-To:References:Sender:Openpgp:Autocrypt;
b=OOri7m//E+w/IsDwO31D08ZZonf3HsyBJxYrqE7i1msnX47nXn3sSdDJQnUHcURUY
q83IxOSL94SUqvpvHBLBA==
The whole purpose of dual-signing is to get mail delivered to servers
that don't deal with ed25519 DKIM signatures. Of course, one can wonder
why one would dual sign in that case, but that's another discussion.
Kind regards,
Edmund
--
Edmund Lodewijks <[email protected]>
TZ: UTC+2 / GMT+2
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]