3 ms·
You cannot "strip off and rewrite" headers without destroying the email message's DKIM signature -- which is the primary assurance of authenticity of incoming e
by pjkundert 4y ago
You cannot "strip off and rewrite" headers without destroying the email message's DKIM signature -- which is the primary assurance of authenticity of incoming email!
Also, you are ensuring that emails from your domain can never reach anyone who has a "forwarding" email address (which is anyone managing any significant number of domains). These people use Cloudflare, etc. to manage the MX for these domains, and forwarding incoming email to their central email address (which remains hidden).
You can't get away from email forwarding; its sort of baked into the underlying assumptions of SMTP, which you are unlikely to single-handedly defeat and replace with something better.
In the mean time, email from your domain will appear "broken" to a vast multitude of the world's email-receiving population.
Your domain, not theirs.
- throwaway67743 4y agoYes, yes you can, that is exactly what you need to do to avoid DKIM failure, you've already broken the ability to verify anything by rewriting the destination. Also see: forwarding is broken (purely forwarding mail via SMTP is not the same as what the comment was about)
- pjkundert 4y agoYou don't "rewrite" the destination (the "To: <address>" header); you just forward the email along using another "RCPT TO: <address>". How do you propose that you "rewrite" headers without breaking DKIM? Any header included in the message's DKIM "h=to:from:... " stanza cannot be changed; they're included in the DKIM signature. You can simply textually include the entire original email in a completely NEW email message, that is DKIM-signed by your intermediate (forwarding) MTA -- but that's not "forwarding", at all -- that's just "sending an email". Is this what you're describing?