On 18 Sep 2015, at 14:29, Bruce Marriner wrote:

So I want to be able to set up Postfix so, if it passes DKIM or other
checks that give me a high confidence then just skip the postgrey stuff
entirely.

In what exactly does a valid DKIM signature give you high confidence? I suspect that this is misplaced...

All a DKIM signature validation tells you is that a message was in fact signed at the mail system where it claimed to have been signed by an entity in control of the DNS for the domain identified the signature and that none of the message fields specified in the DKIM header have been changed in transit. Looking at the spam that has made it through my filters this year, I see that 27% of those messages had a valid DKIM signature, because in fact any spammer who can open a Yahoo account or register a domain can send mail with a valid DKIM signature.

Reply via email to