| | DmitriC 
 
  
 Advanced Member
 | Редактировать | Профиль | Сообщение | Цитировать | Сообщить модератору sVIVs
 Собрал стенд (стенд полностью изолирован от внешней среды, все DNS-имена вымышлены и брались от фонаря, также, как и IP-адреса, поэтому на коллизии DNS-имен и IP адресов с настоящими Internet-сервисами прошу не обращать внимания). Итак:
 
 1. Внутри организации: Домен AD: test.local, почтовый домен: test.com.
 (Windows Server 2016 + Exchange Mailbox 2016) + (Windows Server 2022 + Exchnge Edge 2019 + DkimSigner 3.4.0).
 
 2. Снаружи, так сказать, в интернете: Почтовый домен: gogo.com, почтовый сервер: MDaemon 23.5.2
 
 3. Все необходимые DNS-записи прописаны, включая PTR. Также присутствуют записи SPF и политики DMARC.
 
 Ну что же... работает DkimSigner. Ниже образцы.
 
 Обычное письмо: User1@test.com -> cp@gogo.com
 
 Цитата:
 | Return-path: <User1@test.com> Authentication-Results: mail.gogo.com;
 spf=pass smtp.mailfrom=User1@test.com;
 dkim=pass (good signature) header.d=test.com header.b=Z41E93oeYM;
 dmarc=pass header.from=test.com (p=reject sampling=55 pct=100);
 iprev=pass policy.iprev=41.77.184.10 (PTR mx.test.com);
 iprev=pass policy.iprev=41.77.184.10 (HELO mx.test.com);
 iprev=pass policy.iprev=41.77.184.10 (MAIL User1@test.com)
 Received-SPF: pass (mail.gogo.com: domain test.com
 designates 41.77.184.10 as permitted sender)
 receiver=mail.gogo.com; client-ip=41.77.184.10;
 mechanism=ip4:41.77.184.10; envelope-from="User1@test.com";
 helo=mx.test.com;
 Received: by mail.gogo.com with ESMTPS id md5001000150772.msg; Sat, 12 Oct 2024 23:03:17 +0300
 X-Spam-Processed: mail.gogo.com, Sat, 12 Oct 2024 23:03:17 +0300
 (not processed: sender in recipient's private address book)
 X-MDDKIM-Result: unapproved (mail.gogo.com)
 X-MDSPF-Result: unapproved (mail.gogo.com)
 X-MDRemoteIP: 41.77.184.10
 X-MDHelo: mx.test.com
 X-MDArrival-Date: Sat, 12 Oct 2024 23:03:17 +0300
 X-Rcpt-To: cp@gogo.com
 X-MDRcpt-To: cp@gogo.com
 X-Return-Path: User1@test.com
 X-Envelope-From: User1@test.com
 X-MDaemon-Deliver-To: cp@gogo.com
 DKIM-Signature: v=1; a=rsa-sha256; d=test.com; s=ex; c=simple/simple;
 t=1728763386;
 h=from:subject:to:date:message-id:mime-version:content-type:content-language;
 bh=E/vquJDNxsJ5VO28xhm4XxiP5EvFtJxhnAOmUk0ShrI=;
 b=Z41E93oeYMunDxhclz2m+yqVdzQGOwL0xlHZn+KIWZxem8hFYXEbXRQrKM7z9k1nR8iZ+Vtorre
 SggchCA3qREs4l1XCh8sYnE5TQuI2ochre2FLG3C0TQr/w+oC+F5PjEhiC5CuR0ilMVaZYBt7f7IT
 S5qJUe2LWiU7b2668Co=
 Received: from SRV-EX02.TEST.local (192.168.100.102) by mx.test.com
 (172.16.0.2) with Microsoft SMTP Server (version=TLS1_2,
 cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.2.1544.11; Sat, 12 Oct
 2024 23:03:06 +0300
 Received: from SRV-EX02.TEST.local (192.168.100.102) by SRV-EX02.TEST.local
 (192.168.100.102) with Microsoft SMTP Server (version=TLS1_2,
 cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.1.2507.39; Sat, 12 Oct
 2024 23:03:06 +0300
 Received: from SRV-EX02.TEST.local ([::1]) by SRV-EX02.TEST.local ([::1]) with
 mapi id 15.01.2507.039; Sat, 12 Oct 2024 23:03:06 +0300
 From: =?koi8-r?B?4dfExcXXwSDnwczJzsEg98zBxMnNydLP187B?= <User1@test.com>
 To: "'cp@gogo.com'" <cp@gogo.com>
 Subject: DKIM-Test
 Thread-Topic: DKIM-Test
 Thread-Index: Adsc4b+KQ8cW4qhaSWKafafS3MCA5w==
 Date: Sat, 12 Oct 2024 20:03:06 +0000
 Message-ID: <eab6fd44901d4705927a754e1c1a697f@test.com>
 Accept-Language: ru-RU, en-US
 Content-Language: ru-RU
 X-MS-Has-Attach:
 X-MS-TNEF-Correlator:
 Content-Type: multipart/alternative;
 boundary="_000_eab6fd44901d4705927a754e1c1a697ftestcom_"
 MIME-Version: 1.0
 | 
 
 
 Автоответ на письмо с адреса cp@gogo.com на несуществующий адрес nonexist@test.com:
 
 Цитата:
 | X-Spam-Processed: mail.gogo.com, Sat, 12 Oct 2024 23:28:23 +0300 Return-path: <>
 X-Spam-Level:
 X-Spam-Status: No, score=0.0 required=5.4 tests=HTML_MESSAGE,LOTS_OF_MONEY,
 SPF_HELO_PASS shortcircuit=no autolearn=disabled version=4.0.0
 X-Spam-Report:
 * -0.0 SPF_HELO_PASS SPF: HELO matches SPF record
 *  0.0 HTML_MESSAGE BODY: HTML included in message
 *  0.0 LOTS_OF_MONEY Huge... sums of money
 X-Spam-Checker-Version: SpamAssassin 4.0.0 (2022-12-14)
 Authentication-Results: mail.gogo.com;
 spf=pass smtp.helo=mx.test.com;
 dkim=pass (good signature) header.d=test.com header.b=YEVkoYuGeP;
 dmarc=pass header.from=TEST.com (p=reject sampling=11 pct=100);
 iprev=pass policy.iprev=41.77.184.10 (PTR mx.test.com);
 iprev=pass policy.iprev=41.77.184.10 (HELO mx.test.com);
 iprev=pass policy.iprev=41.77.184.10 (MAIL )
 Received: by mail.gogo.com with ESMTPS id md5001000150775.msg; Sat, 12 Oct 2024 23:28:23 +0300
 X-MDDKIM-Result: unapproved (mail.gogo.com)
 X-MDBP-Result: pass (mail.gogo.com)
 X-MDSPF-Result: unapproved (mail.gogo.com)
 X-MDRemoteIP: 41.77.184.10
 X-MDHelo: mx.test.com
 X-MDArrival-Date: Sat, 12 Oct 2024 23:28:23 +0300
 X-Rcpt-To: cp@gogo.com
 X-MDRcpt-To: cp@gogo.com
 X-Return-Path:
 X-Envelope-From:
 X-MDaemon-Deliver-To: cp@gogo.com
 DKIM-Signature: v=1; a=rsa-sha256; d=test.com; s=ex; c=simple/simple;
 t=1728764873;
 h=from:subject:to:date:message-id:mime-version:content-type:content-language;
 bh=jZuSOEc7irXTkl+49fbyI5Ovrkz0lhGpObm+AyImQ7s=;
 b=YEVkoYuGePAN+KxAFfvk2j0qq6/vJEQxf85M519Ji/3BcWvbYz8ypnr9pHjYABtwQl4yO5jst1g
 JCSpkBT52UHGmuptK22P2zkghkD1NwPXMEv9EGTGeKT/Zq5IULQfha4v9y0J9mG+Ct50OFlCssvuU
 HgEyXO1x8k21fEmR2fs=
 Received: from SRV-EX02.TEST.local (192.168.100.102) by mx.test.com
 (172.16.0.2) with Microsoft SMTP Server (version=TLS1_2,
 cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.2.1544.11; Sat, 12 Oct
 2024 23:27:53 +0300
 MIME-Version: 1.0
 From: <postmaster@TEST.com>
 To: <prvs=10158545e2=cp@gogo.com>
 Date: Sat, 12 Oct 2024 23:27:53 +0300
 Content-Type: multipart/report; report-type=delivery-status;
 boundary="8b6ef7fa-433f-46c6-b7bb-70d87b1fbc8f"
 X-MS-Exchange-Message-Is-Ndr:
 Content-Language: ru
 Message-ID: <3ae5c2b3-033d-45d0-b4e4-c9fe58253a7c@SRV-EX02.TEST.local>
 In-Reply-To: <004001db1ce5$2816c130$78444390$@gogo.com>
 References: <004001db1ce5$2816c130$78444390$@gogo.com>
 Thread-Index: Adsc5SbsqLWcAEuYTqSyudKuF4swOAAAA/+5
 Subject: =?koi8-r?B?7sUg1cTBxdTT0SDEz9PUwdfJ1Ng6IFRlc3Qgbm9uZXhpc3QgYWRkcmVzcw==?=
 Auto-Submitted: auto-replied
 | 
 
 
 
 
 Цитата:
 | Похоже, что проект Exchange DKIM Signer все( Кто что еще использует в связке с Exchange 2019 для DKIM?
 | 
 
 Вместо (Exchange Edge 2019  + DKIM) можно использовать любой почтовый шлюз, умеющий DKIM. Например Kaspersky Secure Mail Gateway или Proxmox Mail Gateway или еще что-нибудь.
 А вообще есть платные DKIM агенты к Exchange. Мне понравился EmailArchitect eaexchdomainkeys. Есть еще DkimX.
 |  | Всего записей: 810 | Зарегистр. 15-12-2005 | Отправлено:  23:39 12-10-2024  | Исправлено: DmitriC,   23:48 13-10-2024
 | 
 |