Hello all,
i am newbie, my proxmox gateway has about a month of use. In this scenario, I am monitoring it closely for false positives (quarantined ham).
Today I saw a message in the quarantine with the following spam info:
The sender was known so I said it is strange that they were assigned a spam level and quarantined. One thing that really caught my eye was the failed DKIM. Sure a failed DKIM raises suspicion.
I went on and clicked on whitelist, the email was sent to the internal server.
The internal server has DKIM verification and it passed (DKIM signature is valid according to internal server).
Question: what is happening ? who is right about DKIM here?
I downloaded the email before whitelisting it, so I could do some tests on it if needed.
i am newbie, my proxmox gateway has about a month of use. In this scenario, I am monitoring it closely for false positives (quarantined ham).
Today I saw a message in the quarantine with the following spam info:
X-SPAM-LEVEL: Spam detection results: 3 BAYES_00 -1.9 Bayes spam probability is 0 to 1% DKIM_INVALID 0.1 DKIM or DK signature exists, but is not valid DKIM_SIGNED 0.1 Message has a DKIM or DK signature, not necessarily valid DMARC_QUAR 0.1 DMARC quarantine policy HEADER_FROM_DIFFERENT_DOMAINS 0.001 From and EnvelopeFrom 2nd level mail domains are different HTML_IMAGE_ONLY_12 2.059 HTML: images with 800-1200 bytes of words HTML_MESSAGE 0.001 HTML included in message HTML_SHORT_LINK_IMG_1 0.001 HTML is very short with a linked image KAM_DMARC_QUARANTINE 3 DKIM has Failed or SPF has failed on the message and the domain has a DMARC quarantine policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment RCVD_IN_DNSWL_NONE -0.0001 Sender listed at https://www.dnswl.org/, no trust RCVD_IN_MSPIKE_H4 0.001 Very Good reputation (+4) RCVD_IN_MSPIKE_WL 0.001 Mailspike good senders SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF recordThe sender was known so I said it is strange that they were assigned a spam level and quarantined. One thing that really caught my eye was the failed DKIM. Sure a failed DKIM raises suspicion.
I went on and clicked on whitelist, the email was sent to the internal server.
The internal server has DKIM verification and it passed (DKIM signature is valid according to internal server).
Question: what is happening ? who is right about DKIM here?
I downloaded the email before whitelisting it, so I could do some tests on it if needed.

