diff --git a/src/content/docs/ispmail-trixie/310-prevent-spoofing-dkim.mdx b/src/content/docs/ispmail-trixie/310-prevent-spoofing-dkim.mdx index eba69be..adb9676 100644 --- a/src/content/docs/ispmail-trixie/310-prevent-spoofing-dkim.mdx +++ b/src/content/docs/ispmail-trixie/310-prevent-spoofing-dkim.mdx @@ -288,6 +288,7 @@ configuration file: cat > /etc/rspamd/local.d/dkim_signing.conf << 'EOF' path = "/var/lib/rspamd/dkim/$domain.$selector.key"; selector_map = "/etc/rspamd/dkim_selectors.map"; +allow_username_mismatch = true; EOF # Restart rspamd @@ -305,6 +306,16 @@ echo example.org 2025100901 > /etc/rspamd/dkim_selectors.map That’s all. rspamd now knows that whenever it sees an outgoing email from `anyone@example.org` it will get the DKIM private key from /var/lib/rspamd/dkim/**example.org**.**2025100901**.key and use it to sign the email. +The `allow_username_mismatch` setting makes rspamd sign an email even if the +authenticated user (during relaying) does not match the actual sender address. +Sounds complicated? Well, the use case is _aliases_. Imagine that +`john@example.com` has an alias address of `pizza@example.org`. If John logs in +as `john@example.org` but chooses to set his sender address to +`pizza@example.org` then rspamd will (by default) not add a DKIM signature due +to a mismatch. Setting `allow_username_mismatch` overrides this behavior and +John's email will be signed even if he sends on behalf of `pizza@example.org`. +(Thanks, DBL, for the hint.) + ### Send a test email You could either just send an email from your mail client (or Roundcube) through your mail server to another email