On Nov 15, 2019, at 9:50 AM, David Jones <djo...@ena.com> wrote:
> 
> If SA is being run post MTA (i.e. inside Thunderbird) then any filtering 
> can change the content to remove potentially bad attachments, add an 
> "EXTERNAL" warning to the Subject or body, etc. which will break DKIM 
> signing.

I believe this is what’s happening on my FPs. My mail flow is sendmail to 
MailScanner to SA (spamc) via procmail, and MS will do some content altering 
(e.g. to disable web bugs or reveal potential phishing links). That breaks 
DKIM. I could disable those features but that obviates half the point of MS. If 
I could swap the order of MS and SA that would resolve this issue... but I’m 
not sure if that’s possible with my setup. (I know MS can call SA from within 
its flow but it doesn’t use spamc/spamd and I think can not accommodate 
per-user prefs.)

The other FP I’ve seen is forwarded mail, I’m not sure why DKIM broke there 
because I didn’t see evidence of MS munging. Will have to examine more closely.

Cheers.

--- Amir
thumbed via iPhone

Reply via email to