Docs / Obsidian Mail Server / Mail flow
Email signing (DKIM)
DKIM (DomainKeys Identified Mail) adds a signature to every message that leaves the server. The receiving server fetches your domain's public key from DNS and checks that the message really comes from your domain and was not changed on the way. Gmail, Outlook.com, Yahoo and most other providers trust signed mail more, and DMARC passes on DKIM even when forwarding breaks SPF. Keys are managed under Email signing (DKIM).
Turn on signing
- Open Email signing (DKIM). Each of your domains has a card.
- Choose Create a signing key. The server makes a 2048-bit RSA key and shows a DNS record:
- Type TXT
- Name like
oms202609._domainkey.example.com(the first part is the key's selector) - Value starting with
v=DKIM1; k=rsa; p=
- Create that record at your DNS provider. Some providers want only the part of the name before your domain (
oms202609._domainkey). The value is long; most providers split it into several quoted strings by themselves. - Wait a few minutes, open the page again, and choose Turn signing on. The server checks that DNS publishes the key first. If you are sure the record is right but DNS is slow, Turn on anyway skips the check.
The Setup guide and the Domains page then show the DKIM record with its status.
What is signed
- Mail leaving the server for another server, signed with the key of the From address's domain. Mail delivered to mailboxes on this server is not signed; it never leaves.
- Only mail the server can vouch for: sent by someone signed in (webmail, phones, mail apps), written by the server itself (non-delivery reports, automatic replies), or relayed from an address in the
RelayFromlist. Mail that arrived from the internet and is forwarded or redirected on is never signed, because its sender was not checked. - The signature covers From, To, Cc, Subject, Date, Message-ID, the reply headers and the body (relaxed canonicalization, so harmless changes in spacing on the way do not break it).
If the domain has no active key, mail goes out unsigned, exactly as before. If signing ever fails, the message is sent unsigned rather than held up.
Rotate the key
Changing keys now and then (for example yearly) limits the damage if a key leaks.
- Choose Rotate key. A new key with a new selector appears under New key waiting.
- Publish its record (the old record stays in place).
- Choose Switch to .... New mail is signed with the new key.
- After a week, delete the old DNS record, and delete the old key under Older keys.
Turn signing off
Stop signing stops signing for the domain right away; the keys are kept, so you can turn it back on later.
From the command line
oms dkim list <org>
oms dkim new <domain> [--bits 2048] (prints the DNS record to create)
oms dkim enable <domain> <selector> (no DNS check: check the record first)
oms dkim disable <domain>