On Fri, Aug 07, 2026 at 12:40:39PM -0400, Paul Tomblin via Postfix-users wrote:
> On Fri, Aug 7, 2026, at 12:23 PM, Jaroslaw Rafa via Postfix-users wrote:
>
> > The certificates only come into play when you are the RECEIVING side.If you
> > are SENDING mail, no certificates are involved on your side, at all.
> >
> > So trouble with SENDING mail to another server cannot be cause dby
> > certificates.
>
> I believe you’re wrong about that. If you sign your email with a
> self-signed certificate, then Google has to trust that certificate in
> order for them to verify your signature. If they decide not to accept
> your self-signed certificate, then they mark your email as a DKIM
> failure.
Sadly, that's quite wrong, and Rafa is right, DKIM signatures are NOT
authenticated by X.509 client certificates. Sending MTAs generally
don't and should not send client certificates. The use of client
certs is typically limited to authentication to smart host relays and
submission servers.
--
Viktor. 🇺🇦 Слава Україні!
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]