Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Configuring DKIM for Fortimail in Transparent Mode
Hello Everyone,
I want to configure DKIM on our Fortimail unit to sign outgoing messages, but I have a lot of questions that I need your help with. First of all, our Fortimail unit is 200F unit, working in transparent mode. We have 2 protected domains configured inside this unit. The two domains are MS exchange servers
For my questions:
- Can I configure the DKIM signing in Transparent mode, or it should be in gateway or server mode for this to work?
- If it is applicable in transparent mode, and I successfully configured it, will this configuration be affected or stop working if I change the working mode of the fortimail unit to gateway mode?
- Do I have to make a record for the DKIM inside my exchange servers internal DNS, or it should be published only on the external DNS?
- Does the protected domains SSL certificates have to be imported inside the Fortimail, or the DKIM has nothing to do with the certificates?
- Is it better to configure the DKIM inside my exchange servers, or it's better to be configured on the Fortimail, and does it have anything to do with the encryption of the email messages (meaning that encrypted messages from the mail server should affect the DKIM if it is configured on the fortimail unit)?
I would greatly appreciate your support on these topics
#Fortimail
Solved! Go to Solution.
Labels:
- Labels:
-
FortiMail
1 Solution
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi ITGuy
- Yes you can configure DKIM signing in transparent mode
- Changing from one mode to another will reset you config to factory defaults, so you will also lose domain config and DKIM private keys as well
- No need for DKIM public key in you private DNS, it should be in your public DNS so remote servers can check it
- DKIM doesn't use any certificate. It needs only a public key and a private key
- I think is better to configure it on FML, I always do that just in case FML changes something in the message or in the headers, in that case the DKIM has to operate at FML level, otherwise it will not be valid anymore
AEK
AEK
2 REPLIES 2
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi ITGuy
- Yes you can configure DKIM signing in transparent mode
- Changing from one mode to another will reset you config to factory defaults, so you will also lose domain config and DKIM private keys as well
- No need for DKIM public key in you private DNS, it should be in your public DNS so remote servers can check it
- DKIM doesn't use any certificate. It needs only a public key and a private key
- I think is better to configure it on FML, I always do that just in case FML changes something in the message or in the headers, in that case the DKIM has to operate at FML level, otherwise it will not be valid anymore
AEK
AEK
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks a lot @AEK
Those answers will help a lot in considering the best approach to apply the DKIM in our configuration
