On Fri, Aug 7, 2026, at 12:23 PM, Jaroslaw Rafa via Postfix-users wrote:
The certificates only come into play when you are the RECEIVING side.If you
are SENDING mail, no certificates are involved on your side, at all.
So trouble with SENDING mail to another server cannot be cause dby
certificates.
On 07.08.26 12:40, Paul Tomblin via Postfix-users wrote:
I believe you’re wrong about that. If you sign your email with a
self-signed certificate, then Google has to trust that certificate in
order for them to verify your signature. If they decide not to accept
your self-signed certificate, then they mark your email as a DKIM failure.
I guess you mistook DKIM and SSL certificates.
DKIM is one story, but DKIM public keys are published in DNS so Google or
other recipients can verify the signature against it.
Sender domain can be protested by DNSSEC, in which case it's pretty safe to
veriy.
Signing e-mail itself (S/MIME or PGP) is different story, usually taken care
of by MUAs, not MTAs.
Using certificate for SSL/TLS client client is also another story
- as previously noted, Let's Encrypt certificates are only for servers, thus
not usable for client connections or S/MIME.
--
Matus UHLAR - fantomas, [email protected] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
Spam = (S)tupid (P)eople's (A)dvertising (M)ethod
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]