This appears rather easy to reproduce. Just include the char 0x0c in a
message, and the signature will be invalid. Playing with the resultant
message, I can make it valid by removing the \x0c character,
suggesting that it's being stripped from whatever rspamd receives for
signing.

Reply via email to