Skip to Content.
Sympa Menu

ddx - DKIM and CNames

Subject: DKIM Deployment

List archive

DKIM and CNames


Chronological Thread 
  • From: Jose-Marcio Martins da Cruz <>
  • To:
  • Subject: DKIM and CNames
  • Date: Fri, 23 Apr 2010 16:04:01 +0200


Hello,

I've just felt on a problem with CNAMES, not related to DKIM, but which can have some implications.

Well, the *default* sendmail configuration has confDONT_EXPAND_CNAMES. Brian Costales Bat Book recommends to change the default configuration to True, which most people don't, as this isn't the default value.

So, consider a hostname defined as (hopefully, there aren't too many) :

lists-one.domain.com. CNAME lists.domain.com.
lists.domain.com. A 1.2.3.4

When sendmail receives this, with the default configuration option it will replace the contents of headers (To:, CC: and probably others too) referencing list-one.domain.com to lists.domain.com.

And this can break DKIM signature.

Did someone other than me already found this ?

Regards

José-Marcio

--



Archive powered by MHonArc 2.6.16.

Top of Page