Re: DKIM for locally generated mails - how best to approach?

2019-02-18 Thread Andrey Repin
Greetings, Viktor Dukhovni! >> There is no need to sign bounces for email that you don't receive >> but what about non-delivery notifications for mail that is accepted >> and then later found to be undeliverable? > In my multi-instance configurations, delivery failure to internal > recipients

Re: DKIM for locally generated mails - how best to approach?

2019-02-18 Thread Viktor Dukhovni
> On Feb 18, 2019, at 2:51 PM, Wietse Venema wrote: > > There is no need to sign bounces for email that you don't receive > but what about non-delivery notifications for mail that is accepted > and then later found to be undeliverable? In my multi-instance configurations, delivery failure to

Re: DKIM for locally generated mails - how best to approach?

2019-02-18 Thread Wietse Venema
Viktor Dukhovni: > On Mon, Feb 18, 2019 at 09:07:36PM +0300, Andrey Repin wrote: > > > > Maybe that should have finer granularity: it may be OK to inspect > > > bounces with Milters, but it may not be OK with header/body_checks. > > > > Yes, I see how this can be a problem. > > Is there a way

Re: DKIM for locally generated mails - how best to approach?

2019-02-18 Thread Viktor Dukhovni
On Mon, Feb 18, 2019 at 09:07:36PM +0300, Andrey Repin wrote: > > Maybe that should have finer granularity: it may be OK to inspect > > bounces with Milters, but it may not be OK with header/body_checks. > > Yes, I see how this can be a problem. > Is there a way around it? How are the

Re: DKIM for locally generated mails - how best to approach?

2019-02-18 Thread Andrey Repin
Greetings, Wietse Venema! > Andrey Repin: >> Greetings, All! >> >> I just discovered that mail generated locally (i.e. introduced by pickup >> daemon) is not signed. >> >> Digging in documentation, I've found >> http://www.postfix.org/postconf.5.html#non_smtpd_milters > That's what I use for

Re: DKIM for locally generated mails - how best to approach?

2019-02-18 Thread Wietse Venema
Andrey Repin: > Greetings, All! > > I just discovered that mail generated locally (i.e. introduced by pickup > daemon) is not signed. > > Digging in documentation, I've found > http://www.postfix.org/postconf.5.html#non_smtpd_milters That's what I use for signing this local submission. > And

Re: DKIM for locally generated mails - how best to approach?

2019-02-18 Thread Dominic Raferd
On Mon, 18 Feb 2019 at 10:51, Andrey Repin wrote: > I just discovered that mail generated locally (i.e. introduced by pickup > daemon) is not signed. > > Digging in documentation, I've found > http://www.postfix.org/postconf.5.html#non_smtpd_milters > But its description made me reluctant to

DKIM for locally generated mails - how best to approach?

2019-02-18 Thread Andrey Repin
Greetings, All! I just discovered that mail generated locally (i.e. introduced by pickup daemon) is not signed. Digging in documentation, I've found http://www.postfix.org/postconf.5.html#non_smtpd_milters But its description made me reluctant to enable it straight away. And then there's