Re: [mailop] opendkim bad signature data from mx.mailop.org

2020-11-07 Thread John Levine via mailop
In article <4cst5s5yn5z8...@mx.mailop.org> you write: >To be honest, my experience among 100+ mail servers, is to reject >On-BadSignature by default, because this blocks an >enormous amount of spam, that wasn't stopped by zen.spamhaus. I'm sure it does but it also blocks mail that users actually

Re: [mailop] opendkim bad signature data from mx.mailop.org

2020-11-07 Thread Jim Popovitch via mailop
On Sat, 2020-11-07 at 17:08 +0100, Jaroslaw Rafa via mailop wrote: > Dnia 7.11.2020 o godz. 11:58:03 Mary via mailop pisze: > > In another mailing list, they automatically replace the From: with > > something like "Mary via listname ", then its easy to > > re-sign the email with the list DKIM sign

Re: [mailop] opendkim bad signature data from mx.mailop.org

2020-11-07 Thread Jaroslaw Rafa via mailop
Dnia 7.11.2020 o godz. 11:58:03 Mary via mailop pisze: > > In another mailing list, they automatically replace the From: with > something like "Mary via listname ", then its easy to > re-sign the email with the list DKIM signature. Replacement of the From: address is usually done only if origina

Re: [mailop] opendkim bad signature data from mx.mailop.org

2020-11-07 Thread Mary via mailop
Thank you all for your suggestions, indeed the issue was the reject parameter. To be honest, my experience among 100+ mail servers, is to reject On-BadSignature by default, because this blocks an enormous amount of spam, that wasn't stopped by zen.spamhaus. In another mailing list, they automa

Re: [mailop] opendkim bad signature data from mx.mailop.org

2020-11-06 Thread John Levine via mailop
In article <7344ec56-6b55-4040-a842-42ec4e488...@graemef.net> you write: >On 6 Nov 2020, at 17:14, SM via mailop wrote: >> The message body is modified as it goes through the list. > >Hrm. Something for us to look at over the weekend - we should be signing the >email with the list’s DKIM config,

Re: [mailop] opendkim bad signature data from mx.mailop.org

2020-11-06 Thread Robert L Mathews via mailop
On 11/6/20 8:05 AM, Mary via mailop wrote: > Here is my opendkim configuration (/etc/opendkim.conf): > ... > On-BadSignature reject Aside from anything else, you shouldn't do this. It violates the rule at the bottom of RFC 6376, section 6.3: If the email cannot be verified, then it SHOU

Re: [mailop] opendkim bad signature data from mx.mailop.org

2020-11-06 Thread Graeme Fowler via mailop
On 6 Nov 2020, at 17:14, SM via mailop wrote: > The message body is modified as it goes through the list. Hrm. Something for us to look at over the weekend - we should be signing the email with the list’s DKIM config, rather than necessarily passing the original signature unaltered. Obviously,

Re: [mailop] opendkim bad signature data from mx.mailop.org

2020-11-06 Thread SM via mailop
Hi Mary, At 08:05 AM 06-11-2020, Mary via mailop wrote: Anyone knows why emails from the list are rejected by opendkim? [snip] On-BadSignature reject The message body is modified as it goes through the list. The DKIM signature verification fails because of that. The above config

[mailop] opendkim bad signature data from mx.mailop.org

2020-11-06 Thread Mary via mailop
Hello everyone, Anyone knows why emails from the list are rejected by opendkim? Here is a short log from mx.mailop.org: postfix/postscreen[18765]: CONNECT from [91.132.147.157]:56468 postfix/postscreen[18765]: PASS OLD [91.132.147.157]:56468 postfix/smtpd[18774]: connect from mx.mailop.org[91.