[MDaemon-L] DKIM certifier failed.

2014-05-22 Terurut Topik Dietrich Edijas
Dear pak syafril,

 

di lampirkan sesi yang kalo gak salah liat gagal di certifier DKIM yang
optsi nya di enable di mdaemon saya.

Pertanyaan saya kalo dugaan saya tidak salah apakah check signature via DKIM
bisa di matikan saja? Kalo Iya impact nya gimana?

 

 

Terima kasih atas infonya,

Didit.

 

Thu 2014-05-22 15:59:19: --

Thu 2014-05-22 15:59:24: [802707] Session 802707; child 0004

Thu 2014-05-22 15:59:24: [802707] Accepting SMTP connection from
[209.85.192.170:49885] to [117.54.9.189:25]

Thu 2014-05-22 15:59:24: [802707] -- 220 mail.bankwindu.com ESMTP MDaemon
14.0.0; Thu, 22 May 2014 15:59:24 +0700

Thu 2014-05-22 15:59:24: [802707] -- EHLO mail-pd0-f170.google.com

Thu 2014-05-22 15:59:24: [802707] -- 250-mail.bankwindu.com Hello
mail-pd0-f170.google.com, pleased to meet you

Thu 2014-05-22 15:59:24: [802707] -- 250-ETRN

Thu 2014-05-22 15:59:24: [802707] -- 250-AUTH LOGIN CRAM-MD5 PLAIN

Thu 2014-05-22 15:59:24: [802707] -- 250-8BITMIME

Thu 2014-05-22 15:59:24: [802707] -- 250-STARTTLS

Thu 2014-05-22 15:59:24: [802707] -- 250 SIZE

Thu 2014-05-22 15:59:24: [802707] -- STARTTLS

Thu 2014-05-22 15:59:24: [802707] -- 220 Begin TLS negotiation

Thu 2014-05-22 15:59:25: [802707] SSL negotiation successful (TLS 1.0, 1024
bit key exchange, 128 bit AES encryption)

Thu 2014-05-22 15:59:25: [802707] -- EHLO mail-pd0-f170.google.com

Thu 2014-05-22 15:59:25: [802707] -- 250-mail.bankwindu.com Hello
mail-pd0-f170.google.com, pleased to meet you

Thu 2014-05-22 15:59:25: [802707] -- 250-ETRN

Thu 2014-05-22 15:59:25: [802707] -- 250-AUTH LOGIN CRAM-MD5 PLAIN

Thu 2014-05-22 15:59:25: [802707] -- 250-8BITMIME

Thu 2014-05-22 15:59:25: [802707] -- 250 SIZE

Thu 2014-05-22 15:59:25: [802707] -- MAIL
FROM:m.sulai...@decilliongroup.com SIZE=153715

Thu 2014-05-22 15:59:25: [802707] Performing IP lookup
(mail-pd0-f170.google.com)

Thu 2014-05-22 15:59:25: [802707] * D=mail-pd0-f170.google.com TTL=(1284)
A=[209.85.192.170]

Thu 2014-05-22 15:59:25: [802707]  End IP lookup results

Thu 2014-05-22 15:59:25: [802707] Performing IP lookup (decilliongroup.com)

Thu 2014-05-22 15:59:26: [802707] * D=decilliongroup.com TTL=(44)
A=[192.185.41.48]

Thu 2014-05-22 15:59:26: [802707] * P=010 S=002 D=decilliongroup.com
TTL=(44) MX=[aspmx.l.google.com]

Thu 2014-05-22 15:59:26: [802707] * P=020 S=004 D=decilliongroup.com
TTL=(44) MX=[alt1.aspmx.l.google.com]

Thu 2014-05-22 15:59:26: [802707] * P=030 S=000 D=decilliongroup.com
TTL=(44) MX=[alt2.aspmx.l.google.com]

Thu 2014-05-22 15:59:26: [802707] * P=040 S=001 D=decilliongroup.com
TTL=(44) MX=[aspmx2.googlemail.com]

Thu 2014-05-22 15:59:26: [802707] * P=050 S=003 D=decilliongroup.com
TTL=(44) MX=[aspmx3.googlemail.com]

Thu 2014-05-22 15:59:26: [802707] * D=decilliongroup.com TTL=(44)
A=[192.185.41.48]

Thu 2014-05-22 15:59:26: [802707] * D=decilliongroup.com TTL=(44)
A=[192.185.41.48]

Thu 2014-05-22 15:59:26: [802707] * D=decilliongroup.com TTL=(44)
A=[192.185.41.48]

Thu 2014-05-22 15:59:27: [802707] * D=decilliongroup.com TTL=(44)
A=[192.185.41.48]

Thu 2014-05-22 15:59:27: [802707] * D=decilliongroup.com TTL=(44)
A=[192.185.41.48]

Thu 2014-05-22 15:59:27: [802707]  End IP lookup results

Thu 2014-05-22 15:59:27: [802707] Performing SPF lookup (decilliongroup.com
/ 209.85.192.170)

Thu 2014-05-22 15:59:27: [802707] * decilliongroup.com 209.85.192.170;
matched to SPF cache

Thu 2014-05-22 15:59:27: [802707] * Result: pass

Thu 2014-05-22 15:59:27: [802707]  End SPF results

Thu 2014-05-22 15:59:27: [802707] -- 250 m.sulai...@decilliongroup.com,
Sender ok

Thu 2014-05-22 15:59:27: [802707] -- RCPT TO:herman.lab...@bankwindu.com

Thu 2014-05-22 15:59:27: [802707] Performing DNS-BL lookup (209.85.192.170 -
connecting IP)

Thu 2014-05-22 15:59:27: [802707] * zen.spamhaus.org - passed

Thu 2014-05-22 15:59:27: [802707]  End DNS-BL results

Thu 2014-05-22 15:59:27: [802707] -- 250 herman.lab...@bankwindu.com,
Recipient ok

Thu 2014-05-22 15:59:27: [802707] -- DATA

Thu 2014-05-22 15:59:27: [802707] Creating temp file (SMTP):
d:\mdaemon\queues\temp\47\md5000144.tmp

Thu 2014-05-22 15:59:27: [802707] -- 354 Enter mail, end with CRLF.CRLF

Thu 2014-05-22 15:59:28: [802707] Message size: 153715 bytes

Thu 2014-05-22 15:59:28: [802707] Performing VBR certification (Domain:
decilliongroup.com, Auth: SPF)

Thu 2014-05-22 15:59:28: [802707] * File:
d:\mdaemon\queues\temp\47\md5000144.tmp

Thu 2014-05-22 15:59:28: [802707] * Message-ID:
!!AAAYAIGiG2ShR49Lv2l4sEdRWRPCgAAAED9ZNs2ELHtLjvjpwssq
owcBAA==@decilliongroup.com

Thu 2014-05-22 15:59:28: [802707] * Certifier (trusted):
vbr.emailcertification.org ...

Thu 2014-05-22 15:59:28: [802707] * Querying:
decilliongroup.com._vouch.vbr.emailcertification.org ...

Thu 2014-05-22 15:59:28: [802707] * Certifier does not recognize that domain

Thu 2014-05-22 15:59:28: [802707] * Certification result: message not
certified

Thu 2014-05-22 15:59:28: [802707]  End VBR results


[MDaemon-L] DKIM certifier failed.

2014-05-22 Terurut Topik Syafril Hermansyah
On 2014-05-22 16:19, Dietrich Edijas wrote:
 di lampirkan sesi yang kalo gak salah liat gagal di certifier DKIM yang
 optsi nya di enable di mdaemon saya.

Ya, opsi itu aktif saat baru diinstall.

 Pertanyaan saya kalo dugaan saya tidak salah apakah check signature via
 DKIM bisa di matikan saja? Kalo Iya impact nya gimana?

- Urgent Update di SecurityPlus akan berhenti berfungsi.
- User Anda rawan terkena phising

https://www.securelist.com/en/threats/spam?chapter=85

misalkan ebay, paypall, yahoo, google menerapkan DKIM sebagai anti
spoofing domain.

Untuk kasus decilliongroup.com kemungkinan baru pindah hosting ke google
mail service dan lupa mengupdate DKIM keys yang dideclare di
authoritative DNSnya sesuai dengan ketentuan google mail sehingga failed.
Hubungi saja pengelola mail domain decilliongroup.com untuk memperbaiki
isian DKIM di DNS servernya.

-- 
syafril
---
Syafril Hermansyah
MDaemon-L Moderators, running MDaemon 14.0.2 SecurityPlus 4.5.0 Beta A
Harap tidak cc: atau kirim ke private mail untuk masalah MDaemon.


-- 
--[MDaemon-L]
Milis ini untuk Diskusi antar pengguna MDaemon Mail Server.

Netiket: http://www.netmeister.org/news/learn2quote
Arsip: http://mdaemon-l.dutaint.com
Dokumentasi : http://mdaemon.dutaint.co.id
Henti Langgan: Kirim mail ke MDaemon-L-unsubscribe [at] dutaint.com
Berlangganan: kirim mail ke MDaemon-L-subscribe [at] dutaint.com
Versi terakhir MD 14.0.2, SP 4.1.5, BES 2.0.2, OC 2.3.3, SG 2.1.2, PP 2.0.1