|
|
| (21 dazwischenliegende Versionen desselben Benutzers werden nicht angezeigt) |
| Zeile 3: |
Zeile 3: |
| ---- | | ---- |
| {{Navigation|<zurück>|<nachste>}} | | {{Navigation|<zurück>|<nachste>}} |
| | {{Navigation|BSI/200-3|BSI/200-3/Einleitung/Beispiele}} |
| ---- | | ---- |
| --> | | --> |
| '''DNS/SPF''' - SPF + DK + DKIM with Postfix | | '''{{BASEPAGENAME}}''' - SPF, DK und DKIM mit Postfix |
| </noinclude> | | </noinclude> |
|
| |
|
| == Beschreibung == | | == Beschreibung == |
| SPF, DK und DKIM mit Postfix
| | <ul class="list-group"> |
| * einrichtet
| | <li class="list-group-item">[[Postfix/Installation|Postfix]]</li> |
| * testen
| | <li class="list-group-item list-group-item-primary">[[Sender Policy Framework]]</li> |
| | | <li class="list-group-item list-group-item-secondary">[[DomainKeys]]</li> |
| == Wechsel auf Postfix ==
| | <li class="list-group-item list-group-item-success">[[DKIM]]</li> |
| apt install postfix
| | <li class="list-group-item list-group-item-danger">[[DNS/SPF/Test|Test]]</li> |
| | | </ul> |
| == SPF == | |
| DNS-Eintrag für SPF
| |
| v=spf1 +a +mx -all
| |
| | |
| SPF ist für diese Domain aktiviert
| |
| | |
| ; Eintrag optimieren
| |
| Wenn Sie mehrere Domains auf Ihrem Server hosten, sollten Sie ihn wahrscheinlich ebenfalls anpassen.
| |
| v=spf1 +a +mx +ip4:<ip.mail> ?all* <tt><ip.mail></tt>
| |
| | |
| Is the IP of the mail server that is responsible for sending the mails, it is automatically filled in when you apply the zones
| |
| | |
| After you do this modification you should apply it
| |
| | |
| Now let’s check with dig if the SPF is OK.
| |
| dig myserverplace.de TXT @ns1.myserverplace.de
| |
| | |
| You will see in the Answer section I have the following entry
| |
| myserverplace.de. 600 IN TXT "v=spf1 +a +mx +ip4:144.76.163.46 ?all"
| |
| | |
| So everything is ok, next onto DomainKeys
| |
| | |
| == [[DomainKeys]] ==
| |
| | |
| == [[DKIM]] ==
| |
| | |
| == Postfix ==
| |
| Now let’s see what we need to do to configure Postfix to use OpenDKIM.
| |
| | |
| Execute the following command to see the milters configured
| |
| | |
| cat /etc/postfix/main.cf | grep "milters"
| |
| smtpd_milters = , inet:127.0.0.1:12768
| |
| non_smtpd_milters = , inet:127.0.0.1:12768
| |
| | |
| Open '''/etc/postfix/main.cf''' with your favorite editor, and add the following to the end of the file
| |
| # OpenDKIM
| |
| milter_default_action = accept
| |
| milter_protocol = 6
| |
| smtpd_milters = , inet:127.0.0.1:8891, inet:127.0.0.1:12768
| |
| non_smtpd_milters = $smtpd_milters
| |
| | |
| And your messages won’t be signed with '''DomainKey''', only with '''DKIM'''
| |
| service postfix restart
| |
| | |
| == Testing ==
| |
| There is an easy way to test if everything is correct, create an email account if you haven’t already and send a test mail to the following recepients, and the results are cut down because the text is too big* check-auth@verifier.port25.com
| |
| | |
| =======================================
| |
| Summary of Results
| |
| =======================================
| |
| SPF check: pass
| |
| DomainKeys check: pass
| |
| DKIM check: pass
| |
| Sender-ID check: pass
| |
| SpamAssassin check: ham* AAAA3QcKCQwA@appmaildev.com
| |
|
| |
| ========================================
| |
| SPF result: Pass
| |
| ========================================
| |
| Domain: myserverplace.de
| |
| IP: 144.76.163.46
| |
|
| |
| SPF Record: myserverplace.de
| |
| IN TXT = "v=spf1 +a +mx 144.76.163.46 ?all"
| |
|
| |
| ========================================
| |
| DomainKey result: pass
| |
| ========================================
| |
| Signed by: admin@myserverplace.de
| |
|
| |
| PublicKey: default._domainkey.myserverplace.de
| |
| IN TXT = "p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDAruBNqdsSCKBLwMrFNNKH8z0e7zmlAic7iRoJsDDJK3IlnW8j6G/T6a93m+jqYc6R38MBAZbeSv2LQJ0SepJEsr4Iqk41WFXPBKnyXReO1RXPW5/YnRe6dpJMEqsmPpl2TjInY7ve/6VCiVDOHn9RRrdB+x7CGeK2crgqSZVlFwIDAQAB;"
| |
|
| |
| ========================================
| |
| DKIM result: pass
| |
| ========================================
| |
| Signed by: admin@myserverplace.de
| |
| Expected Body Hash: frcCV1k9oG9oKj3dpUqdJg1PxRT2RSN/XKdLCPjaYaY=
| |
| PublicKey: mail._domainkey.myserverplace.de
| |
| IN TXT = "v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDMziMcgPTWK0kSUKxrgHHzEiWxNkZ2/M0Ugyr/8H9WtoCsJUM+Bc1C9VwqJ6yjTidecDrX7aL0lFZ9Mylku/wtSiPw6KLxMg2LG2vrMzlPTB2lmJNmg/EOu3KPC8BtAuOhXfwVH/ttQbzdKJKWqiCJn7jhF5oqEKnOCORxOQXKIwIDAQAB;"
| |
| | |
| == Logs ==
| |
| You can check the following locations to see if there are errors
| |
| * /var/log/mail.err
| |
| * /var/log/mail.warn
| |
| * /var/log/mail.info
| |
| * /var/log/syslog
| |
| | |
| == Note ==
| |
| Make sure you enable testing mode for DKIM if you plan to test, you can also cut down the EXPIRY time so the results propagate faster, so to enable testing mode set the key <tt>'''_domainkey'''</tt> to <tt>'''t=y; o=-'''</tt>
| |
| | |
| <!--
| |
| == Aufruf ==
| |
| <syntaxhighlight lang="bash" highlight="1" line copy>
| |
| </syntaxhighlight> | |
| | |
| == Optionen ==
| |
| {| class="table table-striped table-hover sortable options gnu"
| |
| |-
| |
| ! Unix !! GNU !! Parameter !! Beschreibung
| |
| |-
| |
| | || || ||
| |
| |-
| |
| |}
| |
| | |
| == Parameter ==
| |
| == Umgebungsvariablen ==
| |
| == Exit-Status ==
| |
| {| class="table table-striped table-hover options col1center"
| |
| |-
| |
| ! Wert !! Beschreibung
| |
| |-
| |
| | 0 || Erfolg
| |
| |-
| |
| | >0 || Fehler | |
| |}
| |
| -->
| |
| | |
|
| |
|
| <noinclude> | | <noinclude> |
| Zeile 144: |
Zeile 26: |
|
| |
|
| == Anhang == | | == Anhang == |
| == Siehe auch == | | === Siehe auch === |
| <div style="column-count:2"> | | <div style="column-count:2"> |
| <categorytree hideroot=on mode="pages">{{BASEPAGENAME}}</categorytree> | | <categorytree hideroot=on mode="pages">{{BASEPAGENAME}}</categorytree> |
| Zeile 151: |
Zeile 33: |
| {{Special:PrefixIndex/{{BASEPAGENAME}}/}} | | {{Special:PrefixIndex/{{BASEPAGENAME}}/}} |
|
| |
|
| == Dokumentation == | | === Dokumentation === |
| <!-- | | <!-- |
| ; Man-Page | | ; Man-Page |
| Zeile 159: |
Zeile 41: |
| --> | | --> |
|
| |
|
| == Links == | | === Links === |
| === Projekt === | | ==== Projekt ==== |
| === Weblinks === | | ==== Weblinks ==== |
|
| |
|
| <!-- | | <!-- |