Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
prin
New Contributor

Scope of Enable DKIM signing for outgoing messages

Hello everybody,

 

I do have a FortiMail question that may seem very basic but it may potentially have a big impact on the whole configuration. Basically, I just want to make sure that I do understand "Enable DKIM signing for outgoing messages" correctly.

I'm currently in the process of testing DKIM for outgoing messages on a production FortiMail (v. 7.2.0).

  • I've configured the test domain as a separate protected domain,
  • configured a matching selector (is it true that the selector has to be named just like the domain? If so: Why can you even configure different names? It would make sense to use different names if the resulting dns-name is already taken. Moreover, it can only be applied to the protected domain, no associated domains) and
  • downloaded and implemented the TXT in our DNS.

Now, all that seems to be left is to "Enable DKIM signing for outgoing messages" in the SessionProfile for Outgoing Mails. My concern is the following: If I do this, it will be enabled for all of our outgoing mails from our mailserver environment. My guess is that the setting will only be applied to mails that match my test domain that is currently the only domain with a DKIM selector configured on the FortiMail. Is that correct? We do have another protected domain with a number of associatiated domains. Will the setting have any impact on the Domains without a DKIM selector? I see no other way than to enable it for all of our outgoing traffic as it is merely IP-based and session profiles and IP policies cannot be configured domain-based.

 

Thank you in advance for your help!

6 REPLIES 6
Anonymous
Not applicable

Hello @prin,
 
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
 
Thanks,
gtreminio
Staff
Staff

Hi Prin,

 

Based on the information provided, If you enable DKIM signing for outgoing messages for a protected domain from the given settings as shown below:

 

gtreminio_0-1658395303029.png

This setting will be only applied to the domain that is enabled, in your case will be the test domain that has the only DKIM selector configured.

This setting doesn't impact the other domains without the DKIM selector.

Please also notice that you can use any name for the DKIM selector, there is not a restriction in this option.

 

Best regards,

 

prin
New Contributor

Hi gtreminio and Aashiq_Z,

thank you very much for your replies. We'll start testing soon. One more piece of advice: In the Fortinet Document Library it says: "Note that the selector name must match its corresponding domain name (in this example fortinet.com)". Source: docs.fortinet.com If this is incorrent, it should be changed. 

Thanks and kind regards

yoda0815
New Contributor

Hello!


Just implementing DKIM signing of outgoing mails on a FortiMail. FortiMail is acting as a smarthost for M365 mail accounts. At M365 side DKIM signing is deactivated for both initial "onmicrosoft.com" and custom domain.
My understanding is that at FortiMail side BOTH settings
1) "Enable DKIM signing for outgoing messages" in the SessionProfile for outgoing mails
AND
2) "DKIM signing for outgoing email" for the protected domain (together with an active key selector)
have to be enabled in order to effectively have DKIM signing really in place (by FortiMail).
If 1) or 2) is not enabled then there should be no DKIM signing for outgoing mails.


Though my observations are different: If either 1) OR 2) is enabled then the DKIM signature is visible at the mail recipient side (for the mails sent by FortiMail acting as smarthost).

 

Is there anything missing or is my understanding wrong?


Thanks in advance for your feedback !

AEK
Honored Contributor

Hi Yoda

So if I understand well:

 - Use 1 to enable dkim signing at session profile level (cause you may need it disabled on other session profiles)

 - Use 2 to enable it globally for the domain

(My assumption needs to be double checked)

AEK
AEK
yoda0815
New Contributor

Hi AEK,

Yes - 1) and 2) settings are both enabled, so DKIM signing is taking place - as expected.

But I would expect that if one of "DKIM signing for outgoing messages/email" setting in 1) OR 2) is disabled then DKIM signing should NOT take place. In fact it needs only one of both settings to have DKIM signing in place (as observed at mail recipient side).

 

Yoda

Labels
Top Kudoed Authors