This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

DKIM not signing NDR from internal servers

Hi,

I have recently configured DMARC and DKIM on our XG450 Units (18.0.1 MR-1-Build396), currently no policy is being applied while I monitor results.

I have noticed most, if not all, of the responses to failure reports are NDR's generated by our internal exchange servers. It appears that the XG is passing these emails without applying the DKIM signature.

Exchange has a rule configured to "reject the message and include the explanation 'User Account is disabled' with the status code: '5.7.1'"

Examining the header information of the copy of the email returned in the failure report shows other Sophos header information but no sign of DKIM, normal email sent are working as expected.

Please let me know if you require examples or any log content to identify the cause.



This thread was automatically locked due to age.
Parents
  • DKIM on the XG is pretty buggy still. You'll get DKIM verification problems on inbound e-mail where there are multiple DKIM signatures for example.

    I've found it easier to turn off DKIM on the XG and use dkim-exchange on the Exchange Server.

    If you do want DKIM signing for everything else except the Exchange Server, create a rule prior to the auto-created rule that scans SMTP/SMTPS and have this new rule configured for the Exchange Server as a source and SMTP/SMTPS for the destination protocol and to not scan SMTP/SMTPS.

  • Thanks for the tips, I haven't even got to the step of enabling DKIM Verification, I was just looking to clean up all outgoing sources first, so I am just monitoring outgoing email at the moment. The bulk, if not all our email is exchange generated so it sounds like that might be our best course of action.

Reply
  • Thanks for the tips, I haven't even got to the step of enabling DKIM Verification, I was just looking to clean up all outgoing sources first, so I am just monitoring outgoing email at the moment. The bulk, if not all our email is exchange generated so it sounds like that might be our best course of action.

Children
No Data