Why T_DKIM_INVALID ?

General discussions and other topics.
3 posts Page 1 of 1
by lr » Fri Sep 13, 2013 10:20 am
I've been tuning the spamassassin parameters for my account a little bit; I've managed to get the spam that doesn't go into the greymail to be down to a few messages per day (tolerable).

In doing so, I noticed one strange thing. Lots of ham (good messages, from real people, sent from reputable ISPs or hosts) trigger the T_DKIM_INVALID test. Meaning their systems are misconfigured to generate bad DKIM. The list includes my kid's high school principal (using the school district's system, and this is a very large, wealthy and sophisticated district), a building contractor using his default SBC e-mail address that comes with his DSL, and my son's instrument teacher using his default Comcast e-mail. These are not smart but sloppy computer hackers, who think they configured DKIM but got it wrong, but non-computer folks using preconfigured systems.

On the other hand, a large fraction of the spam that still makes it through the filters also has T_DKIM_INVALID (makes sense, much of it forges the address).

The bad news: This means I can't use T_DKIM_INVALID to help seriously suppress the remaining spam.

The annoying part: Why do administrators for large systems not configure DKIM correctly?

This is not a complaint about Sonic, nor is the e-mail configuration problem Sonic-specific. I'm just venting that adjusting my spamassassin parameters is hard or impossible, because the world is full of fail. Thank you for listening to my rant.
Linda and Ralph and John
by kgc » Fri Sep 13, 2013 10:29 am
Ralph, I just checked and mail from gmail is getting correctly flagged with DKIM_SIGNED & DKIM_VALID so this isn't a site wide problem validating DKIM. As to the other part, correctly configuring DKIM/SPF can be problematic, especially in cases where the administrators are unable to fully control the mail flow. We haven't enabled either for @sonic.net for these reasons and others.
Kelsey Cummings
System Architect, Sonic.net, Inc.
by lr » Fri Sep 13, 2013 11:50 am
Kelsey: Thanks for looking. I had already looked that for most of my mail (the ham) the DKIM is verified correctly.

It's annoying that we can't use DKIM more extensively. Oh well, life.
Linda and Ralph and John
3 posts Page 1 of 1