Implementing domainlkeys signature
Implementing domainlkeys signature
No rush, but it may be a good idea to try to implement Yahoo's domainkeys system to combat spam. I see that gmail has implemented this too.
See the details in:
http://antispam.yahoo.com/domainkeys
and in
http://domainkeys.sourceforge.net/
See the details in:
http://antispam.yahoo.com/domainkeys
and in
http://domainkeys.sourceforge.net/
Duplicate request of this one here:
http://www.hmailserver.com/forum/viewto ... domainkeys
Although that one doesn't have the two question poll interface.
http://www.hmailserver.com/forum/viewto ... domainkeys
Although that one doesn't have the two question poll interface.
Even beter if DKIM
DK seems to have evolved to "DomainKeys Identified Mail (DKIM)", wich provides tools to fight spam and pishing even better than DK.
I think that if Martin decides to implement DK, should try to do the work only once and support DK and DKIM (in fact I think DK is a subset of DKIM functions).
Best regards,
Info:
http://mipassoc.org/dkim/
http://www.ietf.org/internet-drafts/dra ... ase-00.txt
http://files.altn.com/MDaemon/White_Pap ... Daemon.pdf
Ignasi
I think that if Martin decides to implement DK, should try to do the work only once and support DK and DKIM (in fact I think DK is a subset of DKIM functions).
Best regards,
Info:
http://mipassoc.org/dkim/
http://www.ietf.org/internet-drafts/dra ... ase-00.txt
http://files.altn.com/MDaemon/White_Pap ... Daemon.pdf
Ignasi
-
- Senior user
- Posts: 886
- Joined: 2005-11-28 11:43
Hope so ! But I think it's poll ranking and Martin's decision.
Anyway Martin seems to be very interested in impementing spam fighting tools for 4.3, maybe will give some extra points to spam fighting related feature requests.... but anyway it's Martin who's gona have to make it so he'll decide
Anyway Martin seems to be very interested in impementing spam fighting tools for 4.3, maybe will give some extra points to spam fighting related feature requests.... but anyway it's Martin who's gona have to make it so he'll decide

My perfect combination:
hMailServer 5.6.1 (B2208), ASSP 1.3.3.8 (antispam), Clamav 0.98.6 (antivirus)
hMailServer 5.6.1 (B2208), ASSP 1.3.3.8 (antispam), Clamav 0.98.6 (antivirus)
Just came here to vote 'yes' - the voting buttons aren't there any more. (uh, at least for me :)
Was that because it's being implemented in 4.3 or after?
My ISP (cablemodem - Comcast) doesn't support SPF on their server and since I send via their server when at home, I can't use SPF for my domain. Haven't looked at Domain keys yet (nor DKIM at all...) so I don't know if I can use that, but I'd sure like both SPF and DK/DKIM in hMailServer!
- Al Weiner -
Was that because it's being implemented in 4.3 or after?
My ISP (cablemodem - Comcast) doesn't support SPF on their server and since I send via their server when at home, I can't use SPF for my domain. Haven't looked at Domain keys yet (nor DKIM at all...) so I don't know if I can use that, but I'd sure like both SPF and DK/DKIM in hMailServer!
- Al Weiner -
-
- Normal user
- Posts: 249
- Joined: 2006-06-26 07:14
- Location: Melbourne, Australia
- Contact:
Hi Martin, are you asking for more info about DKIM ? Weren't the links supplied at the beginning of this thread enough ? maybe you are asking for more info about Hotmail incompatibility problems (which I don't know anything about) ?
My perfect combination:
hMailServer 5.6.1 (B2208), ASSP 1.3.3.8 (antispam), Clamav 0.98.6 (antivirus)
hMailServer 5.6.1 (B2208), ASSP 1.3.3.8 (antispam), Clamav 0.98.6 (antivirus)
-
- Normal user
- Posts: 249
- Joined: 2006-06-26 07:14
- Location: Melbourne, Australia
- Contact:
DKIM won't help you for sending to Hotmail. They use SenderID and their own SmartScreen technology. Funny thing is that SenderID was canned by ITEF, yet Microsoft pushed on even though the PRA element of SenderID (which was developed by Microsoft themselves as I understand it) was fundamentally flawed as it is incompatible with SPF. If you have an SPF policy in place, then it is very likely that this could be the very cause of why you can't send to Hotmail. Your SPF policy might well be ok, but what you'll need to do is set up a specific PRA policy in addition to your SPF policy. Confused yet?
I did this a month or so ago and email from my domain are now starting to filter through to Hotmail accounts, although it is still hit and miss.
I did this a month or so ago and email from my domain are now starting to filter through to Hotmail accounts, although it is still hit and miss.
DomainKeys is now officially a proposed standard by the IETF (SenderID still is not!):
http://news.com.com/Promising%20antispa ... l?part=rss
http://news.com.com/Promising%20antispa ... l?part=rss
Good to know ! 
Although I think there's no plans to include it in V5, seems there's a look of work with Unicode and the former feature requests:
Shared folders when using IMAP (93 votes) Under development
SSL server support (92 votes) Under development
SpamAssasin Integration (66 votes) No info at this moment
Implementing domainlkeys signature (46 votes) No info at this moment but we can expect at least that the previous one must be done before this.
Anyway I'm sure sooner or later this will be implemented in hMailServer.

Although I think there's no plans to include it in V5, seems there's a look of work with Unicode and the former feature requests:
Shared folders when using IMAP (93 votes) Under development
SSL server support (92 votes) Under development
SpamAssasin Integration (66 votes) No info at this moment
Implementing domainlkeys signature (46 votes) No info at this moment but we can expect at least that the previous one must be done before this.
Anyway I'm sure sooner or later this will be implemented in hMailServer.
My perfect combination:
hMailServer 5.6.1 (B2208), ASSP 1.3.3.8 (antispam), Clamav 0.98.6 (antivirus)
hMailServer 5.6.1 (B2208), ASSP 1.3.3.8 (antispam), Clamav 0.98.6 (antivirus)
Please implement DK and DKIM
Any clues on how you are feeling about adding this feature?
-
- New user
- Posts: 1
- Joined: 2008-01-15 03:29
-
- New user
- Posts: 2
- Joined: 2008-02-18 17:30
Implementing domainlkeys signature
I voted yes to this feature, I have hmail as my email software and the only thing missing for my email validation is Implementing domainlkeys signature
Does anybody know how long it will be untill this feature is added?
Does anybody know how long it will be untill this feature is added?
Vote for DKM
A lot of push on this subject. Anyone see this?
http://www.networkworld.com/news/2008/0 ... ising.html
I vote yes to implement RFC 4871 DKIM
http://www.networkworld.com/news/2008/0 ... ising.html
I vote yes to implement RFC 4871 DKIM
-
- New user
- Posts: 1
- Joined: 2008-05-20 02:29
Re: Implementing domainlkeys signature
Is this going to be implemented soon? I'm running a Drupal site on my own dedicated server running hMailServer but a lot of my mails from Drupal are getting rejected as spam (namely new registration e-mails). In the message headers in Yahoo it says neutral DomainKeys (no sig). I'm also seeing my messages being blocked by MSN and Google, even though SPF is fine and shows that it is authenticating correctly. Seems DKIM is becoming the new measuring stick.
Re: Implementing domainlkeys signature
Is this in the 5.0 Ver?..... We need it to handle Yahoo
They move a great deal of email to the "SPAM" bucket - because we don't have the domain keys.
They move a great deal of email to the "SPAM" bucket - because we don't have the domain keys.
hmailsvr 4.4/5.1 ~MS-SQL 2000/2008 ~VB6,VB.NET 2005~ASP.NET
Re: Implementing domainlkeys signature
No, probably in 5.1. I think it's already possible to set up a script to accomplish it though:
http://www.hmailserver.com/forum/viewto ... f=7&t=3797
http://www.hmailserver.com/forum/viewto ... f=7&t=3797
-
- New user
- Posts: 7
- Joined: 2007-08-07 07:36
Re: Implementing domainlkeys signature
Its all about the smtp host name and Ip address, then you can send and recive emails from any were no one can block your emails.
How...?
first think is that you have to give your smtp a valid host name, whose ip address is same as your smtp server, and your IP shount not be listed in any SPAM blacklisted.
If the above given condition is matched then no one can block your emails from your mail server. one more think is that you need to set your Ip address reverse lookup to your domain name some of the IP address have this format....
xx.xx.xx.xx.xyz.net.nz so all ip series have this xyz.net.nz is attached if one of that IP is listed then all the series which contains this domain xyz.net.nz attached all are got blacklisted.
so this is the mails problem now days ISP's are doing they add their domain name in their Ip ranges so a end users cant use that IP for commercial use like hosting etc.... you need a IP address which dont have domain name format in your Ip range you can check your IP address name format in http://www.ip-adress.com/ipaddresstolocation/
Birender
How...?
first think is that you have to give your smtp a valid host name, whose ip address is same as your smtp server, and your IP shount not be listed in any SPAM blacklisted.
If the above given condition is matched then no one can block your emails from your mail server. one more think is that you need to set your Ip address reverse lookup to your domain name some of the IP address have this format....
xx.xx.xx.xx.xyz.net.nz so all ip series have this xyz.net.nz is attached if one of that IP is listed then all the series which contains this domain xyz.net.nz attached all are got blacklisted.
so this is the mails problem now days ISP's are doing they add their domain name in their Ip ranges so a end users cant use that IP for commercial use like hosting etc.... you need a IP address which dont have domain name format in your Ip range you can check your IP address name format in http://www.ip-adress.com/ipaddresstolocation/
Birender
Re: Implementing domainlkeys signature
Hotmail doesn't use DKIM or Domain Keys... but Yahoo does! Unfortunately Yahoo uses Domain Keys but NOT DKIM - so you need to implement both.
Re: Implementing domainlkeys signature
Why would I implement an obsolete technology just because Yahoo use it? Yahoo has participated in creating the new standard and also participated in marking the old standard, Domain Keys, as obsolete. DomainKeys Identified Mail will be implemented, Domain Keys will not.JohnnyW wrote:Hotmail doesn't use DKIM or Domain Keys... but Yahoo does! Unfortunately Yahoo uses Domain Keys but NOT DKIM - so you need to implement both.
Re: Implementing domainlkeys signature
Anyone here who has used Domain keys before?
I'm thinking of which options to make configurable, so if anyone has any opinions....
Signing
In every domain
Server-wide setting
The tagging will be made just before hMailServer starts to deliver the messages (after the global rules have been run but before the actual delivery is made).
I'm thinking of which options to make configurable, so if anyone has any opinions....

Signing
In every domain
- Enable DKIM
- Private key file (location)
- Selector string
Server-wide setting
- Enable DKIM
- Score
The tagging will be made just before hMailServer starts to deliver the messages (after the global rules have been run but before the actual delivery is made).
Re: Implementing domainlkeys signature
Moving to archive since it's included in 5.1.