Update dist for prod

This commit is contained in:
forgejo-actions[bot] 2026-08-01 23:43:19 +00:00
parent 4cd001bdf3
commit 3759974880
39 changed files with 29 additions and 20 deletions

View file

@ -221,13 +221,22 @@ specified otherwise in a map. Always use a specific selector so that you can lat
into trouble.</p>
<p>Using maps is simple. First we need to change the <em>selector_map</em> setting of the dkim_signing module. Create a new rspamd
configuration file:</p>
<div class="expressive-code"><figure class="frame is-terminal has-title not-content"><figcaption class="header"><span class="title">Run this on your server</span></figcaption><pre data-language="sh"><code><div class="ec-line"><div class="code"><span style="--0:#919F9F;--1:#5F636F"># Tell rspamd to look up selectors in our mapping file</span></div></div><div class="ec-line"><div class="code"><span style="--0:#82AAFF;--1:#3B61B0">cat</span><span style="--0:#D6DEEB;--1:#403F53"> </span><span style="--0:#7FDBCA;--1:#096E72">></span><span style="--0:#D6DEEB;--1:#403F53"> </span><span style="--0:#ECC48D;--1:#3B61B0">/etc/rspamd/local.d/dkim_signing.conf</span><span style="--0:#D6DEEB;--1:#403F53"> </span><span style="--0:#7FDBCA;--1:#096E72">&#x3C;&#x3C;</span><span style="--0:#D6DEEB;--1:#403F53"> </span><span style="--0:#D9F5DD;--1:#111111">'EOF'</span></div></div><div class="ec-line"><div class="code"><span style="--0:#ECC48D;--1:#984E4D">path = "/var/lib/rspamd/dkim/$domain.$selector.key";</span></div></div><div class="ec-line"><div class="code"><span style="--0:#ECC48D;--1:#984E4D">selector_map = "/etc/rspamd/dkim_selectors.map";</span></div></div><div class="ec-line"><div class="code"><span style="--0:#D9F5DD;--1:#111111">EOF</span></div></div><div class="ec-line"><div class="code">
</div></div><div class="ec-line"><div class="code"><span style="--0:#919F9F;--1:#5F636F"># Restart rspamd</span></div></div><div class="ec-line"><div class="code"><span style="--0:#82AAFF;--1:#3B61B0">systemctl</span><span style="--0:#D6DEEB;--1:#403F53"> </span><span style="--0:#ECC48D;--1:#3B61B0">restart</span><span style="--0:#D6DEEB;--1:#403F53"> </span><span style="--0:#ECC48D;--1:#3B61B0">rspamd</span></div></div></code></pre><div class="copy"><div aria-live="polite"></div><button title="Copy to clipboard" data-copied="Copied!" data-code="# Tell rspamd to look up selectors in our mapping filecat > /etc/rspamd/local.d/dkim_signing.conf << &#x27;EOF&#x27;path = &#x22;/var/lib/rspamd/dkim/$domain.$selector.key&#x22;;selector_map = &#x22;/etc/rspamd/dkim_selectors.map&#x22;;EOF# Restart rspamdsystemctl restart rspamd"><div></div></button></div></figure></div>
<div class="expressive-code"><figure class="frame is-terminal has-title not-content"><figcaption class="header"><span class="title">Run this on your server</span></figcaption><pre data-language="sh"><code><div class="ec-line"><div class="code"><span style="--0:#919F9F;--1:#5F636F"># Tell rspamd to look up selectors in our mapping file</span></div></div><div class="ec-line"><div class="code"><span style="--0:#82AAFF;--1:#3B61B0">cat</span><span style="--0:#D6DEEB;--1:#403F53"> </span><span style="--0:#7FDBCA;--1:#096E72">></span><span style="--0:#D6DEEB;--1:#403F53"> </span><span style="--0:#ECC48D;--1:#3B61B0">/etc/rspamd/local.d/dkim_signing.conf</span><span style="--0:#D6DEEB;--1:#403F53"> </span><span style="--0:#7FDBCA;--1:#096E72">&#x3C;&#x3C;</span><span style="--0:#D6DEEB;--1:#403F53"> </span><span style="--0:#D9F5DD;--1:#111111">'EOF'</span></div></div><div class="ec-line"><div class="code"><span style="--0:#ECC48D;--1:#984E4D">path = "/var/lib/rspamd/dkim/$domain.$selector.key";</span></div></div><div class="ec-line"><div class="code"><span style="--0:#ECC48D;--1:#984E4D">selector_map = "/etc/rspamd/dkim_selectors.map";</span></div></div><div class="ec-line"><div class="code"><span style="--0:#ECC48D;--1:#984E4D">allow_username_mismatch = true;</span></div></div><div class="ec-line"><div class="code"><span style="--0:#D9F5DD;--1:#111111">EOF</span></div></div><div class="ec-line"><div class="code">
</div></div><div class="ec-line"><div class="code"><span style="--0:#919F9F;--1:#5F636F"># Restart rspamd</span></div></div><div class="ec-line"><div class="code"><span style="--0:#82AAFF;--1:#3B61B0">systemctl</span><span style="--0:#D6DEEB;--1:#403F53"> </span><span style="--0:#ECC48D;--1:#3B61B0">restart</span><span style="--0:#D6DEEB;--1:#403F53"> </span><span style="--0:#ECC48D;--1:#3B61B0">rspamd</span></div></div></code></pre><div class="copy"><div aria-live="polite"></div><button title="Copy to clipboard" data-copied="Copied!" data-code="# Tell rspamd to look up selectors in our mapping filecat > /etc/rspamd/local.d/dkim_signing.conf << &#x27;EOF&#x27;path = &#x22;/var/lib/rspamd/dkim/$domain.$selector.key&#x22;;selector_map = &#x22;/etc/rspamd/dkim_selectors.map&#x22;;allow_username_mismatch = true;EOF# Restart rspamdsystemctl restart rspamd"><div></div></button></div></figure></div>
<p>The configuration is simple. rspamd will look for the domain-to-key mapping in the <code dir="auto">dkim_selectors.map</code> file. Create
that file for your own domain and selector:</p>
<div class="expressive-code"><figure class="frame is-terminal has-title not-content"><figcaption class="header"><span class="title">Run this on your server</span></figcaption><pre data-language="sh"><code><div class="ec-line"><div class="code"><span style="--0:#919F9F;--1:#5F636F"># Add the mapping of domain/selector (use your own domain here)</span></div></div><div class="ec-line"><div class="code"><span style="--0:#C5E478;--1:#3B61B0">echo</span><span style="--0:#D6DEEB;--1:#403F53"> </span><span style="--0:#ECC48D;--1:#3B61B0">example.org</span><span style="--0:#D6DEEB;--1:#403F53"> </span><span style="--0:#F78C6C;--1:#AA0982">2025100901</span><span style="--0:#D6DEEB;--1:#403F53"> </span><span style="--0:#7FDBCA;--1:#096E72">></span><span style="--0:#D6DEEB;--1:#403F53"> </span><span style="--0:#ECC48D;--1:#3B61B0">/etc/rspamd/dkim_selectors.map</span></div></div></code></pre><div class="copy"><div aria-live="polite"></div><button title="Copy to clipboard" data-copied="Copied!" data-code="# Add the mapping of domain/selector (use your own domain here)echo example.org 2025100901 > /etc/rspamd/dkim_selectors.map"><div></div></button></div></figure></div>
<p>Thats all. rspamd now knows that whenever it sees an outgoing email from <code dir="auto">anyone@example.org</code> it will get the DKIM
private key from /var/lib/rspamd/dkim/<strong>example.org</strong>.<strong>2025100901</strong>.key and use it to sign the email.</p>
<p>The <code dir="auto">allow_username_mismatch</code> setting makes rspamd sign an email even if the
authenticated user (during relaying) does not match the actual sender address.
Sounds complicated? Well, the use case is <em>aliases</em>. Imagine that
<code dir="auto">john@example.com</code> has an alias address of <code dir="auto">pizza@example.org</code>. If John logs in
as <code dir="auto">john@example.org</code> but chooses to set his sender address to
<code dir="auto">pizza@example.org</code> then rspamd will (by default) not add a DKIM signature due
to a mismatch. Setting <code dir="auto">allow_username_mismatch</code> overrides this behavior and
Johns email will be signed even if he sends on behalf of <code dir="auto">pizza@example.org</code>.
(Thanks, DBL, for the hint.)</p>
<div class="sl-heading-wrapper level-h3"><h3 id="send-a-test-email">Send a test email</h3><a class="sl-anchor-link" href="#send-a-test-email"><span aria-hidden="true" class="sl-anchor-icon"><svg width="16" height="16" viewBox="0 0 24 24" fill="currentColor"><path d="m12.11 15.39-3.88 3.88a2.52 2.52 0 0 1-3.5 0 2.47 2.47 0 0 1 0-3.5l3.88-3.88a1 1 0 1 0-1.42-1.42l-3.88 3.89a4.48 4.48 0 0 0 6.33 6.33l3.89-3.88a1 1 0 0 0-1.42-1.42m8.58-12.08a4.49 4.49 0 0 0-6.33 0l-3.89 3.88a1 1 0 1 0 1.42 1.42l3.88-3.88a2.52 2.52 0 0 1 3.5 0 2.47 2.47 0 0 1 0 3.5l-3.88 3.88a1 1 0 0 0 0 1.42 1 1 0 0 0 1.42 0l3.88-3.89a4.49 4.49 0 0 0 0-6.33M8.83 15.17a1 1 0 0 0 .71.29 1 1 0 0 0 .71-.29l4.92-4.92a1 1 0 1 0-1.42-1.42l-4.92 4.92a1 1 0 0 0 0 1.42"></path></svg></span><span class="sr-only" data-pagefind-ignore>Section titled “Send a test email”</span></a></div>
<p>You could either just send an email from your mail client (or Roundcube) through your mail server to another email
address. Or you could use swaks. Use your own addresses and password of course:</p>