I am unsure how long this has been failing for as it was working fine when i initially set it up.
I updated mailcow a couple of weeks ago but did not check this immediately so that may have had something to do with it.
The DKIM check was failling said key was missing. I have confirmed that DNS record is correct i have also deleted and regenerated new DKIM key.
This is what i am receiving when i check it;
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=itmunky.com.au;
s=dkim; t=1544676607;
h=from:from:sender:reply-to:subject:subject:date:date:message-id:to:to:
cc:mime-version:mime-version:content-type:content-type:
content-transfer-encoding:in-reply-to:references;
bh=0FF28E15UupfrbUXEzM5Fm5xJhLBFe6rLJZ6eHla+lA=;
b=S+AVMp2Jt1HhDAZNrOaTUe4PqoqGXjf4N/Hf/4gbfpn41rwA93XNgOTi92kcVjYAHFi10L
Gtk4xGY6/ldQirGnoR6V53mYB8wKJIZmXwIR1n1AfRR0f1QfiiGAElTxFSac2X/oLretVi
ptkh/hB8TAPTjoinDIJW6h+EBRaGbA+gIfHq8LVw2BBdjqhCrWN3UvR8TtnJP2NUwn9xwf
oSly6NdxGCBMXg2D+5FiH4Wt2Ov8H6ED9d8VXc0jxix4BMLBZgfESO8u/At6DIKWTjEc6p
qaugDiZ2TbeNF5/SIATCvcxP9XTENkcqkqTUE2jz1U63dQPWIMMtECn4qoindQ==
Signed-by: [email protected]
Expected-Body-Hash: 0FF28E15UupfrbUXEzM5Fm5xJhLBFe6rLJZ6eHla+lA=
DKIM-Result: permerror (no key)
Any ideas?
Hello,
Are you sure your DNS records are correct?
I can't find any DNS record for the DKIM selector you set up
I can't find any DNS record for the DKIM selector you set up
This has to be the biggest facepalm moment in my adult life.
Sometimes the 2nd set of eyes is all you need. Thanks for that buddy.
Hmm, it seems I still cannot get this to work. I have tried using 2048 and now 1024 which is what it was using successfully beforehand.
Am I still missing something obvious.
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=itmunky.com.au;
s=dkim; t=1545092377;
h=from:from:sender:reply-to:subject:subject:date:date:message-id:to:to:
cc:mime-version:mime-version:content-type:content-type:
content-transfer-encoding:in-reply-to:references;
bh=kkMAWSr9UJtjx2WTmTqKC0LrZQKSZm0pxbMCwLXz3qY=;
b=ZAy2RFXEdsfLei8IiyjQdY2pLyPjMNdD/lzWagu/SLfxsIDUnaYRX1bI4h/pJCki4zYgLb
LqHFSJewPfk4iy+aQLs7Gieu1is3zgKzoVbYGLAMM5KT6npy7ZeI4DHSPsE13mHr162u8z
oZYyvqy6JubWxFJRqztP/q77eMbig94=
Signed-by: [email protected]
Expected-Body-Hash: kkMAWSr9UJtjx2WTmTqKC0LrZQKSZm0pxbMCwLXz3qY=
Public-Key: v=DKIM1;k=rsa;t=s;s=email;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC6QjzOVMKH7wmEeGtEhV9cfWV1OSntKZ6NykX8UwtmdngnBbSkXa/old7fKDavrAtok48u8gvaGyY0Z2i0tlcW2OhjGEEwX6+g29AzUnXoD/wHVa6oSVkmEtN8YV4w9eU0VlJf1kBFnUIaI3WAZhxI21yO/DvNXgA/VkpbK1lljwIDAQAB;
DKIM-Result: fail (bad signature)
Could you try again ?
Maybe the DNS changes were not fully propagated when you tried.
I checked the DKIM record and it looks correct.
Also, you can check your DNS records on the mailcow UI. Configuration > Mail setup on the menu. Then you have a blue "DNS" button per domain.
Cool i didn't even know that DNS records per domain was a thing.

Looks ok from what i can see. Just tested it again but still getting the same result.
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=itmunky.com.au;
s=dkim; t=1545264697;
h=from:from:sender:reply-to:subject:subject:date:date:message-id:to:to:
cc:mime-version:mime-version:content-type:content-type:
content-transfer-encoding:in-reply-to:references;
bh=9wtFaGpmlZHJ6FZFeyDsiIokf4Sc7K/49E04tl5g6cI=;
b=ty5CqMirvEkVHyCpk7M8ObaNxD0QcA6oOuQbOg7SSi8RPU8Li9E7sZ/NGIUzYxo35S/n+k
oeHpWTDJn1/CqgXuTW6/r+COcRnZIia1q4d9l8HQsZgcq0r2b/ZmZkj8boR+cGJ2hT5FuO
wu8qQSH7LgE7nsv5XFNOv7fO71psMIU=
Signed-by: [email protected]
Expected-Body-Hash: 9wtFaGpmlZHJ6FZFeyDsiIokf4Sc7K/49E04tl5g6cI=
Public-Key: v=DKIM1;k=rsa;t=s;s=email;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQC6QjzOVMKH7wmEeGtEhV9cfWV1OSntKZ6NykX8UwtmdngnBbSkXa/old7fKDavrAtok48u8gvaGyY0Z2i0tlcW2OhjGEEwX6+g29AzUnXoD/wHVa6oSVkmEtN8YV4w9eU0VlJf1kBFnUIaI3WAZhxI21yO/DvNXgA/VkpbK1lljwIDAQAB;
DKIM-Result: fail (bad signature)
I just tried from another domain I am hosting and it works fine.
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=wanneroolacrosse.com;
s=s1024; t=1545265000; h=from:from:sender:reply-to:subject:subject:date:date:
message-id:message-id:to:to:cc:mime-version:mime-version:
content-type:content-type:content-transfer-encoding:in-reply-to:
references; bh=qnbpNPRlFTsLiyyuwO4Qas8oC0ErPE9qIY1ZeVn7DWs=;
b=Zck7Hx+xpaxCp+4t+e6wrs6sc9VW2E/IGpj7TMtxwsSzyJ3qxISSuhob/Q2D8iPOuRJx9Q
jhjbMd4TndcZPOqwhbSpfnTTVImRnsOxP+EEvp445j6niphEYr2uylmjQATJpVF6b7pwT3
EqzKgE87nVGO7MH6W//jUtkSef0i5Q0=
Signed-by: [email protected]
Expected-Body-Hash: qnbpNPRlFTsLiyyuwO4Qas8oC0ErPE9qIY1ZeVn7DWs=
Public-Key: v=DKIM1;k=rsa;t=s;s=email;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCtpzetJXYlAZXCSFdG4AOaaFZQ0ST+wTr/MwjSvo8+9pDHPQWwfE7bL/oZKSyESXz1nZqLp8rhJHXY9YqVDMosePYCqP8h6S7rCvqnST9iaTIPWZIQMekwzRkNZW8ufkABYSniJLB9ZD1SheQxYcXdAUsAmoT0kJ5Dr0jmNbuY2wIDAQAB;
DKIM-Result: pass
Hi,
Sorry for the late reply. Did you solve your problem?
I can't find the cause of the problem.
Make sure that all the DNS records have a green tick icon next to it.
I wouldn't say i know what the problem is. But i know what is causing it. Windows 10 Mail App.
I just did some testing and it is still failing, but if i send from SOGo webmail, works perfectly!
Go Figure!
Just did a test from my phone aswell using Nine and it works fine also.
i have the same Error. Any news?
No logs, no news. :o
But seriously, there is not a general problem with this. Probably a crashed/offline Redis or something like that, I'd guess.
You could try to add debug_modules = ["dkim"] to data/conf/rspamd/override.d/logging.inc and restart rspamd-mailcow. Post rspamd-mailcow logs when you send a mail, which is not being signed.
@stampydh I had a similar experience in the pass
the issue was my dns provider aka name.com was supporting no more than 1024bits while the DKIM I was generating and trying to add was 2048bits.
No error message was provided
they (name.com) was just trunking the DNS entry.
So; to be sure this is not your case
you could try to regenerate a 1024bits DKIM
wait 48hours than test again with mxtoolbox
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.