Hello!
I am really liking Proxmox mail gateway so far and feel it is a perfect solution for my customer. However, I cannot get past DKIM validation errors. Any suggestions you have would be very appreciated.
SETUP INFO
I have stood up a new install of Proxmox Mail Gateway 9.0.1.
I have modified the Mail Proxy > Ports so that internal smtp port is 25 and external is 26. This was done because this test setup is to be an onprem relay to the internet.
I have enabled Mail Proxy > DKIM
Enable DKIM signing = Yes
Selector = dmz2
Signing Domain Source = Envelope
Sign all outgoing mail = yes
Mail Proxy > DKIM > View DNS record shows:
dmz2._domainkey IN TXT ( "v=DKIM1; h=sha256; k=rsa; "
"p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzmOukeMVAYBtV6Srf1h/SNosc4XP69LXoyF7M3E6BnVQAVYR8ma9KVAFIuASM9bxEn0XaqGOtDrnXOgepXddHWzHzp2dmvEQFZGownCE2gfZEkk3tNvxb1CZmDQ2d/5K4j1wozGCtm050t1Lgms9fN/Q2Vmo7mYktKiSn0fBEPGaYsM0vibUAJVWx2MUD7iKnmMtxOp1jkLFWU"
"WD3yVFqcRHHJZKC2sJngXi+Yjz/xmPu4pf3+zsP2zDJAEEnXpH7WuoOcqdVPL9e5Fs1MA90x4g+5ftpMWThLdjIaT5DoMq4AK4yHK2BS31LHMAmEeS8vQ3eh4ggTRuwk+RdMDwQQIDAQAB" ) ; ----- DKIM key dmz2
Externally in the public DNS, the following record exists as a TXT record
dmz2._domainkey.<mydomain>
v=DKIM1; h=sha256; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzmOukeMVAYBtV6Srf1h/SNosc4XP69LXoyF7M3E6BnVQAVYR8ma9KVAFIuASM9bxEn0XaqGOtDrnXOgepXddHWzHzp2dmvEQFZGownCE2gfZEkk3tNvxb1CZmDQ2d/5K4j1wozGCtm050t1Lgms9fN/Q2Vmo7mYktKiSn0fBEPGaYsM0vibUAJVWx2MUD7iKnmMtxOp1jkLFWUWD3yVFqcRHHJZKC2sJngXi+Yjz/xmPu4pf3+zsP2zDJAEEnXpH7WuoOcqdVPL9e5Fs1MA90x4g+5ftpMWThLdjIaT5DoMq4AK4yHK2BS31LHMAmEeS8vQ3eh4ggTRuwk+RdMDwQQIDAQAB
TEST INFO
- Validate DKIM DNS record using mxtoolbox.com shows success
- Generate test email by telneting to proxmox on port 25 and run ehlo, mail from, rcpt to, data
- Generating test email for validation using https://redsift.com/tools/investigate shows SPF success and DKIM failure:
"error": "bad signature",<br> "explanation": "crypto/rsa: verification error",<br> "source": 0,<br> "tag": "b"
- Sending test email to gmail and m365 shows dkim failure
- Fortigate firewall infront of the proxmox but no inspection or AV is occurring. Packet capture on each side of the firewall shows no modification.
Do you have any suggested next steps for me to try?
I am really liking Proxmox mail gateway so far and feel it is a perfect solution for my customer. However, I cannot get past DKIM validation errors. Any suggestions you have would be very appreciated.
SETUP INFO
I have stood up a new install of Proxmox Mail Gateway 9.0.1.
I have modified the Mail Proxy > Ports so that internal smtp port is 25 and external is 26. This was done because this test setup is to be an onprem relay to the internet.
I have enabled Mail Proxy > DKIM
Enable DKIM signing = Yes
Selector = dmz2
Signing Domain Source = Envelope
Sign all outgoing mail = yes
Mail Proxy > DKIM > View DNS record shows:
dmz2._domainkey IN TXT ( "v=DKIM1; h=sha256; k=rsa; "
"p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzmOukeMVAYBtV6Srf1h/SNosc4XP69LXoyF7M3E6BnVQAVYR8ma9KVAFIuASM9bxEn0XaqGOtDrnXOgepXddHWzHzp2dmvEQFZGownCE2gfZEkk3tNvxb1CZmDQ2d/5K4j1wozGCtm050t1Lgms9fN/Q2Vmo7mYktKiSn0fBEPGaYsM0vibUAJVWx2MUD7iKnmMtxOp1jkLFWU"
"WD3yVFqcRHHJZKC2sJngXi+Yjz/xmPu4pf3+zsP2zDJAEEnXpH7WuoOcqdVPL9e5Fs1MA90x4g+5ftpMWThLdjIaT5DoMq4AK4yHK2BS31LHMAmEeS8vQ3eh4ggTRuwk+RdMDwQQIDAQAB" ) ; ----- DKIM key dmz2
Externally in the public DNS, the following record exists as a TXT record
dmz2._domainkey.<mydomain>
v=DKIM1; h=sha256; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzmOukeMVAYBtV6Srf1h/SNosc4XP69LXoyF7M3E6BnVQAVYR8ma9KVAFIuASM9bxEn0XaqGOtDrnXOgepXddHWzHzp2dmvEQFZGownCE2gfZEkk3tNvxb1CZmDQ2d/5K4j1wozGCtm050t1Lgms9fN/Q2Vmo7mYktKiSn0fBEPGaYsM0vibUAJVWx2MUD7iKnmMtxOp1jkLFWUWD3yVFqcRHHJZKC2sJngXi+Yjz/xmPu4pf3+zsP2zDJAEEnXpH7WuoOcqdVPL9e5Fs1MA90x4g+5ftpMWThLdjIaT5DoMq4AK4yHK2BS31LHMAmEeS8vQ3eh4ggTRuwk+RdMDwQQIDAQAB
TEST INFO
- Validate DKIM DNS record using mxtoolbox.com shows success
- Generate test email by telneting to proxmox on port 25 and run ehlo, mail from, rcpt to, data
- Generating test email for validation using https://redsift.com/tools/investigate shows SPF success and DKIM failure:
"error": "bad signature",<br> "explanation": "crypto/rsa: verification error",<br> "source": 0,<br> "tag": "b"
- Sending test email to gmail and m365 shows dkim failure
- Fortigate firewall infront of the proxmox but no inspection or AV is occurring. Packet capture on each side of the firewall shows no modification.
Do you have any suggested next steps for me to try?
