[mdaemon-l] DKIM Validator

2021-02-17 Terurut Topik Syafril Hermansyah via mdaemon-l
On 18/02/21 10.09, Slamet Raharjo wrote:
> Mohon arahan, bagaimanakah cara generate DKIM Key jika di satu mail server
> yang sama ada multiple domain, saya cek yang domain ini masih invalid untuk
> DKIM, sbb :

> Message contains this DKIM Signature:
> DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
>   d=pocarisweat.id; s=MDaemon; t=1613617497; x=161497;
>   i=ad...@pocarisweat.id; q=dns/txt; h=Date:From:To:Subject:
>   MIME-Version:Content-Type:Message-ID; bh=vthVnUo+d/znrODB1TJTQm/
>   4UksF64azj3Zw23SmJ4Y=; b=QhJbBVlM7HwdzPshrKn+AIMWHgMYioZXOCf7rPt
>   LwPjApL1b5aQPWobMq0Lsa+uurjEZvujhBDNFHghT8hAUWokQ7tCTS8/YoulW6/C
>   WgDigPgZWIIah50lkrY6cwHP6K36wDNhRRQRytrvXOS/E850X4mLte3Bt0Ru0yHD
>   fpos=


Public Key DKIM record sudah ada (benar) di MDaemon mail.aio.co.id


> Building DNS Query for MDaemon._domainkey.pocarisweat.id
> Retrieved this publickey from DNS: 
> Validating Signature
> 
> result = invalid
> Details: public key: not available


DNS DKIM record untuk domain pocarisweat.id belum dibuat di Name Server
ns1.cbn.net.id.

> Retrieved this SPF Record: zone updated 20210218 (TTL = 599)
> using authoritative server (ns2.cbn.net.id) directly for SPF Check
> Result: none (No applicable sender policy available)
> 
> Result code: none


DNS SPF record juga belum dibuat di Name Server ns1.cbn.net.id.

-- 
syafril

Syafril Hermansyah

MDaemon-L Moderator, run MDaemon 21.0.1 Beta A 64bit
Mohon tidak kirim private mail (atau cc:) untuk masalah MDaemon.

Semua hal atau semua kesulitan dan semua pemborosan sebetulnya bisa kita atasi,
kalau mau. Jadi permasalahannya adalah bukan bisa atau tidak bisa, tapi mau atau
tidak mau.
--- Dahlan Iskan



-- 
--[mdaemon-l]--
Milis ini untuk Diskusi antar pengguna MDaemon Mail Server di Indonesia

Netiket: https://wiki.openstack.org/wiki/MailingListEtiquette
Arsip: http://mdaemon-l.dutaint.com
Dokumentasi : http://mdaemon.dutaint.co.id
Berlangganan: Kirim mail ke mdaemon-l-subscr...@dutaint.com
Henti Langgan: Kirim mail ke mdaemon-l-unsubscr...@dutaint.com
Versi terakhir: MDaemon 21.0, SecurityGateway 7.0.2




[mdaemon-l] DKIM Validator

2021-02-17 Terurut Topik Slamet Raharjo
Dear Pak Syafril,

Mohon arahan, bagaimanakah cara generate DKIM Key jika di satu mail server
yang sama ada multiple domain, saya cek yang domain ini masih invalid untuk
DKIM, sbb :

Received: from mail.aio.co.id (mail.aio.co.id [202.158.62.55])
by relay-6.us-west-2.relay-prod (Postfix) with ESMTP id B224320DCB
for ; Thu, 18 Feb 2021 03:05:02
+ (UTC)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=pocarisweat.id; s=MDaemon; t=1613617497; x=161497;
i=ad...@pocarisweat.id; q=dns/txt; h=Date:From:To:Subject:
MIME-Version:Content-Type:Message-ID; bh=vthVnUo+d/znrODB1TJTQm/
4UksF64azj3Zw23SmJ4Y=; b=QhJbBVlM7HwdzPshrKn+AIMWHgMYioZXOCf7rPt
LwPjApL1b5aQPWobMq0Lsa+uurjEZvujhBDNFHghT8hAUWokQ7tCTS8/YoulW6/C
WgDigPgZWIIah50lkrY6cwHP6K36wDNhRRQRytrvXOS/E850X4mLte3Bt0Ru0yHD
fpos=
X-MDAV-Result: clean
X-MDAV-Processed: mail.aio.co.id, Thu, 18 Feb 2021 10:04:57 +0700
Received: from WorldClient.aio.co.id by pocarisweat.id with ESMTPA id
md50026336992.msg; 
Thu, 18 Feb 2021 10:04:55 +0700
X-Spam-Processed: mail.aio.co.id, Thu, 18 Feb 2021 10:04:55 +0700
(not processed: message from trusted or authenticated source)
X-MDOP-RefID:
str=0001.0A673423.602DD954.0097,ss=1,re=0.000,recu=0.000,reip=0.000,cl=1,cld
=1,fgs=0 (_st=1 _vt=0 _iwf=0)
X-MDArrival-Date: Thu, 18 Feb 2021 10:04:55 +0700
X-Authenticated-Sender: ad...@pocarisweat.id
X-Return-Path: prvs=16833c631e=ad...@pocarisweat.id
X-Envelope-From: ad...@pocarisweat.id
X-MDaemon-Deliver-To: vaibblci2km...@dkimvalidator.com
Received: by pocarisweat.id via MDaemon Webmail with HTTP;
Thu, 18 Feb 2021 10:04:43 +0700
Date: Thu, 18 Feb 2021 10:04:43 +0700
From: "Admin Pocarisweat" 
To: vaibblci2km...@dkimvalidator.com
Subject: Test Validator
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="0218-0304-43-03-PART_BREAK"
Message-ID: 
X-Mailer: MDaemon Webmail 19.5.5

--0218-0304-43-03-PART_BREAK
Content-Type: text/plain; charset="us-ascii"


Test Validator
--0218-0304-43-03-PART_BREAK
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable






Test V=
alidator


--0218-0304-43-03-PART_BREAK--

DKIM Information:
DKIM Signature

Message contains this DKIM Signature:
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=pocarisweat.id; s=MDaemon; t=1613617497; x=161497;
i=ad...@pocarisweat.id; q=dns/txt; h=Date:From:To:Subject:
MIME-Version:Content-Type:Message-ID; bh=vthVnUo+d/znrODB1TJTQm/
4UksF64azj3Zw23SmJ4Y=; b=QhJbBVlM7HwdzPshrKn+AIMWHgMYioZXOCf7rPt
LwPjApL1b5aQPWobMq0Lsa+uurjEZvujhBDNFHghT8hAUWokQ7tCTS8/YoulW6/C
WgDigPgZWIIah50lkrY6cwHP6K36wDNhRRQRytrvXOS/E850X4mLte3Bt0Ru0yHD
fpos=


Signature Information:
v= Version: 1
a= Algorithm:   rsa-sha256
c= Method:  relaxed/relaxed
d= Domain:  pocarisweat.id
s= Selector:MDaemon
q= Protocol:dns/txt
bh= vthVnUo+d/znrODB1TJTQm/
4UksF64azj3Zw23SmJ4Y=
h= Signed Headers:  Date:From:To:Subject:
MIME-Version:Content-Type:Message-ID
b= Data:QhJbBVlM7HwdzPshrKn+AIMWHgMYioZXOCf7rPt
LwPjApL1b5aQPWobMq0Lsa+uurjEZvujhBDNFHghT8hAUWokQ7tCTS8/YoulW6/C
WgDigPgZWIIah50lkrY6cwHP6K36wDNhRRQRytrvXOS/E850X4mLte3Bt0Ru0yHD
fpos=
Public Key DNS Lookup

Building DNS Query for MDaemon._domainkey.pocarisweat.id
Retrieved this publickey from DNS: 
Validating Signature

result = invalid
Details: public key: not available

SPF Information:
Using this information that I obtained from the headers

Helo Address = mail.aio.co.id
>From Address = ad...@pocarisweat.id
>From IP  = 202.158.62.55
SPF Record Lookup

Looking up TXT SPF record for pocarisweat.id
Found the following namesevers for pocarisweat.id: ns2.cbn.net.id
ns1.cbn.net.id
Retrieved this SPF Record: zone updated 20210218 (TTL = 599)
using authoritative server (ns2.cbn.net.id) directly for SPF Check
Result: none (No applicable sender policy available)

Result code: none
Local Explanation: pocarisweat.id: No applicable sender policy available
spf_header = Received-SPF: none (pocarisweat.id: No applicable sender policy
available) receiver=dkimvalidator.com; identity=mailfrom;
envelope-from="ad...@pocarisweat.id"; helo=mail.aio.co.id;
client-ip=202.158.62.55

SpamAssassin Score: -4.798
Message is NOT marked as spam
Points breakdown: 
-5.0 RCVD_IN_DNSWL_HI   RBL: Sender listed at https://www.dnswl.org/,
high trust
[202.158.62.55 listed in list.dnswl.org]
 0.0 SPF_HELO_NONE  SPF: HELO does not publish an SPF Record
 0.0 HTML_MESSAGE   BODY: HTML included in message
 0.1 DKIM_SIGNEDMessage has a DKIM or DK signature, not
necessarily
valid
 0.1 DKIM_INVALID   DKIM or DK signature exists, but is not valid

Best Regards,

Slamet Raharjo
IT Dept.



--