This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

DKIM not signing NDR from internal servers

Hi,

I have recently configured DMARC and DKIM on our XG450 Units (18.0.1 MR-1-Build396), currently no policy is being applied while I monitor results.

I have noticed most, if not all, of the responses to failure reports are NDR's generated by our internal exchange servers. It appears that the XG is passing these emails without applying the DKIM signature.

Exchange has a rule configured to "reject the message and include the explanation 'User Account is disabled' with the status code: '5.7.1'"

Examining the header information of the copy of the email returned in the failure report shows other Sophos header information but no sign of DKIM, normal email sent are working as expected.

Please let me know if you require examples or any log content to identify the cause.



This thread was automatically locked due to age.
Parents
  • Hello IT Services17,

    Thank you for contacting the Sophos Community!

    Did you update the TXT record on the DNS server? 

    You should be able to find information about the email under the /log/smtpd_main.log

    You might need to put it in debug mode 

    service smtpd:debug -ds nosync

    Regards,

  • Thanks for the reply, yes all DNS TXT records are updated and working, as mentioned above all my standard emails are being signed as expected, it is just NDRs and Out of Office responses generated by the internal exchange system that seem to pass through the sophos without DKIM signing.

    I'll see if I can get some results with debug logging enabled.

Reply
  • Thanks for the reply, yes all DNS TXT records are updated and working, as mentioned above all my standard emails are being signed as expected, it is just NDRs and Out of Office responses generated by the internal exchange system that seem to pass through the sophos without DKIM signing.

    I'll see if I can get some results with debug logging enabled.

Children
No Data