Update dist for prod
This commit is contained in:
parent
4cd001bdf3
commit
3759974880
39 changed files with 29 additions and 20 deletions
|
|
@ -221,13 +221,22 @@ specified otherwise in a map. Always use a specific selector so that you can lat
|
|||
into trouble.</p>
|
||||
<p>Using maps is simple. First we need to change the <em>selector_map</em> setting of the dkim_signing module. Create a new rspamd
|
||||
configuration file:</p>
|
||||
<div class="expressive-code"><figure class="frame is-terminal has-title not-content"><figcaption class="header"><span class="title">Run this on your server</span></figcaption><pre data-language="sh"><code><div class="ec-line"><div class="code"><span style="--0:#919F9F;--1:#5F636F"># Tell rspamd to look up selectors in our mapping file</span></div></div><div class="ec-line"><div class="code"><span style="--0:#82AAFF;--1:#3B61B0">cat</span><span style="--0:#D6DEEB;--1:#403F53"> </span><span style="--0:#7FDBCA;--1:#096E72">></span><span style="--0:#D6DEEB;--1:#403F53"> </span><span style="--0:#ECC48D;--1:#3B61B0">/etc/rspamd/local.d/dkim_signing.conf</span><span style="--0:#D6DEEB;--1:#403F53"> </span><span style="--0:#7FDBCA;--1:#096E72"><<</span><span style="--0:#D6DEEB;--1:#403F53"> </span><span style="--0:#D9F5DD;--1:#111111">'EOF'</span></div></div><div class="ec-line"><div class="code"><span style="--0:#ECC48D;--1:#984E4D">path = "/var/lib/rspamd/dkim/$domain.$selector.key";</span></div></div><div class="ec-line"><div class="code"><span style="--0:#ECC48D;--1:#984E4D">selector_map = "/etc/rspamd/dkim_selectors.map";</span></div></div><div class="ec-line"><div class="code"><span style="--0:#D9F5DD;--1:#111111">EOF</span></div></div><div class="ec-line"><div class="code">
|
||||
</div></div><div class="ec-line"><div class="code"><span style="--0:#919F9F;--1:#5F636F"># Restart rspamd</span></div></div><div class="ec-line"><div class="code"><span style="--0:#82AAFF;--1:#3B61B0">systemctl</span><span style="--0:#D6DEEB;--1:#403F53"> </span><span style="--0:#ECC48D;--1:#3B61B0">restart</span><span style="--0:#D6DEEB;--1:#403F53"> </span><span style="--0:#ECC48D;--1:#3B61B0">rspamd</span></div></div></code></pre><div class="copy"><div aria-live="polite"></div><button title="Copy to clipboard" data-copied="Copied!" data-code="# Tell rspamd to look up selectors in our mapping filecat > /etc/rspamd/local.d/dkim_signing.conf << 'EOF'path = "/var/lib/rspamd/dkim/$domain.$selector.key";selector_map = "/etc/rspamd/dkim_selectors.map";EOF# Restart rspamdsystemctl restart rspamd"><div></div></button></div></figure></div>
|
||||
<div class="expressive-code"><figure class="frame is-terminal has-title not-content"><figcaption class="header"><span class="title">Run this on your server</span></figcaption><pre data-language="sh"><code><div class="ec-line"><div class="code"><span style="--0:#919F9F;--1:#5F636F"># Tell rspamd to look up selectors in our mapping file</span></div></div><div class="ec-line"><div class="code"><span style="--0:#82AAFF;--1:#3B61B0">cat</span><span style="--0:#D6DEEB;--1:#403F53"> </span><span style="--0:#7FDBCA;--1:#096E72">></span><span style="--0:#D6DEEB;--1:#403F53"> </span><span style="--0:#ECC48D;--1:#3B61B0">/etc/rspamd/local.d/dkim_signing.conf</span><span style="--0:#D6DEEB;--1:#403F53"> </span><span style="--0:#7FDBCA;--1:#096E72"><<</span><span style="--0:#D6DEEB;--1:#403F53"> </span><span style="--0:#D9F5DD;--1:#111111">'EOF'</span></div></div><div class="ec-line"><div class="code"><span style="--0:#ECC48D;--1:#984E4D">path = "/var/lib/rspamd/dkim/$domain.$selector.key";</span></div></div><div class="ec-line"><div class="code"><span style="--0:#ECC48D;--1:#984E4D">selector_map = "/etc/rspamd/dkim_selectors.map";</span></div></div><div class="ec-line"><div class="code"><span style="--0:#ECC48D;--1:#984E4D">allow_username_mismatch = true;</span></div></div><div class="ec-line"><div class="code"><span style="--0:#D9F5DD;--1:#111111">EOF</span></div></div><div class="ec-line"><div class="code">
|
||||
</div></div><div class="ec-line"><div class="code"><span style="--0:#919F9F;--1:#5F636F"># Restart rspamd</span></div></div><div class="ec-line"><div class="code"><span style="--0:#82AAFF;--1:#3B61B0">systemctl</span><span style="--0:#D6DEEB;--1:#403F53"> </span><span style="--0:#ECC48D;--1:#3B61B0">restart</span><span style="--0:#D6DEEB;--1:#403F53"> </span><span style="--0:#ECC48D;--1:#3B61B0">rspamd</span></div></div></code></pre><div class="copy"><div aria-live="polite"></div><button title="Copy to clipboard" data-copied="Copied!" data-code="# Tell rspamd to look up selectors in our mapping filecat > /etc/rspamd/local.d/dkim_signing.conf << 'EOF'path = "/var/lib/rspamd/dkim/$domain.$selector.key";selector_map = "/etc/rspamd/dkim_selectors.map";allow_username_mismatch = true;EOF# Restart rspamdsystemctl restart rspamd"><div></div></button></div></figure></div>
|
||||
<p>The configuration is simple. rspamd will look for the domain-to-key mapping in the <code dir="auto">dkim_selectors.map</code> file. Create
|
||||
that file for your own domain and selector:</p>
|
||||
<div class="expressive-code"><figure class="frame is-terminal has-title not-content"><figcaption class="header"><span class="title">Run this on your server</span></figcaption><pre data-language="sh"><code><div class="ec-line"><div class="code"><span style="--0:#919F9F;--1:#5F636F"># Add the mapping of domain/selector (use your own domain here)</span></div></div><div class="ec-line"><div class="code"><span style="--0:#C5E478;--1:#3B61B0">echo</span><span style="--0:#D6DEEB;--1:#403F53"> </span><span style="--0:#ECC48D;--1:#3B61B0">example.org</span><span style="--0:#D6DEEB;--1:#403F53"> </span><span style="--0:#F78C6C;--1:#AA0982">2025100901</span><span style="--0:#D6DEEB;--1:#403F53"> </span><span style="--0:#7FDBCA;--1:#096E72">></span><span style="--0:#D6DEEB;--1:#403F53"> </span><span style="--0:#ECC48D;--1:#3B61B0">/etc/rspamd/dkim_selectors.map</span></div></div></code></pre><div class="copy"><div aria-live="polite"></div><button title="Copy to clipboard" data-copied="Copied!" data-code="# Add the mapping of domain/selector (use your own domain here)echo example.org 2025100901 > /etc/rspamd/dkim_selectors.map"><div></div></button></div></figure></div>
|
||||
<p>That’s all. rspamd now knows that whenever it sees an outgoing email from <code dir="auto">anyone@example.org</code> it will get the DKIM
|
||||
private key from /var/lib/rspamd/dkim/<strong>example.org</strong>.<strong>2025100901</strong>.key and use it to sign the email.</p>
|
||||
<p>The <code dir="auto">allow_username_mismatch</code> setting makes rspamd sign an email even if the
|
||||
authenticated user (during relaying) does not match the actual sender address.
|
||||
Sounds complicated? Well, the use case is <em>aliases</em>. Imagine that
|
||||
<code dir="auto">john@example.com</code> has an alias address of <code dir="auto">pizza@example.org</code>. If John logs in
|
||||
as <code dir="auto">john@example.org</code> but chooses to set his sender address to
|
||||
<code dir="auto">pizza@example.org</code> then rspamd will (by default) not add a DKIM signature due
|
||||
to a mismatch. Setting <code dir="auto">allow_username_mismatch</code> overrides this behavior and
|
||||
John’s email will be signed even if he sends on behalf of <code dir="auto">pizza@example.org</code>.
|
||||
(Thanks, DBL, for the hint.)</p>
|
||||
<div class="sl-heading-wrapper level-h3"><h3 id="send-a-test-email">Send a test email</h3><a class="sl-anchor-link" href="#send-a-test-email"><span aria-hidden="true" class="sl-anchor-icon"><svg width="16" height="16" viewBox="0 0 24 24" fill="currentColor"><path d="m12.11 15.39-3.88 3.88a2.52 2.52 0 0 1-3.5 0 2.47 2.47 0 0 1 0-3.5l3.88-3.88a1 1 0 1 0-1.42-1.42l-3.88 3.89a4.48 4.48 0 0 0 6.33 6.33l3.89-3.88a1 1 0 0 0-1.42-1.42m8.58-12.08a4.49 4.49 0 0 0-6.33 0l-3.89 3.88a1 1 0 1 0 1.42 1.42l3.88-3.88a2.52 2.52 0 0 1 3.5 0 2.47 2.47 0 0 1 0 3.5l-3.88 3.88a1 1 0 0 0 0 1.42 1 1 0 0 0 1.42 0l3.88-3.89a4.49 4.49 0 0 0 0-6.33M8.83 15.17a1 1 0 0 0 .71.29 1 1 0 0 0 .71-.29l4.92-4.92a1 1 0 1 0-1.42-1.42l-4.92 4.92a1 1 0 0 0 0 1.42"></path></svg></span><span class="sr-only" data-pagefind-ignore>Section titled “Send a test email”</span></a></div>
|
||||
<p>You could either just send an email from your mail client (or Roundcube) through your mail server to another email
|
||||
address. Or you could use swaks. Use your own addresses and password of course:</p>
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue