Good afternoon,

I filed this at https://github.com/OpenSMTPD/OpenSMTPD/issues/1318, but it 
seems it might be better sent here. If that’s the wrong list / way, please let 
me know.

The filter directive in smtpd.conf allows to add the dkimfilter on a listen 
directive in smtpd.conf. However, there might be setups, where this is not 
sufficient, consider the following shortened and pseudo-coded smtpd.conf

filter "dkimsign" proc-exec "filter-dkimsign ..." user ... group ...
listen on 192.0.2.15 port 587 ... filter "dkimsign"

action "sendviagmail" relay host secure://....gmail.com auth ...
action "regular" relay

match from any mail-from "[email protected]" for any action "sendviagmail"
match from any for any action "regular"

Now anything send via gmail would have my DKIM signature on it as well, which 
by definition it should not have.

However, if I could add the filter directive to the
action "regular" relay filter "dkimsign"
it would work as intended.

I'm uncertain whether this would qualify as a bug report or a feature request. 
It could be a bug in that signatures would be added in an unexpected manner, 
since the „action“ follows processing after the listener. And based on the 
processing, DKIM signatures might not be needed.

I know that I could construct ugly workarounds, such as having another listener 
port for anything that should not be signed or sending anything that should be 
signed to another port, have it signed and then relaay, however, this isn't 
exactly logical or a clean design: The DKIM signature should in fact establish 
some kind of trust into the sender, which isn’t the listener ;-)

(And I know, that since there is a workaround, this could be a feature request. 
However, the workaround adds additional Received headers, which in turn might 
not be wanted)

The change would also solve https://github.com/OpenSMTPD/OpenSMTPD/issues/1272

Best regards

Tobias

Reply via email to