Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Scott_Cuff
New Contributor

Webmail sent does not include DKIM

Hi:

 

I have a Fortimail 200d in Server Mode running latest firmware 5.3.8 (627).

When I send an email from Outlook to whoever it sends DKIM and DMARC info.

If I do the same email via  webmail e.g. https://mail.fm200d.com/mail  it sends but no DKIM is sent?

Same user same domain for both Outlook and Webmail

In IP Policies I have 0000 to 00000 with session that has DKIM send

Looks like Webmail does not use the Session?

Is there any fix or workaround?

 

Thanks,

Scott

 

 

7 REPLIES 7
abelio
SuperUser
SuperUser

Hi Scott

 

when sending with webmail:  could you check your logs in order to verify matching against your ip policy id?

 

 

regards




/ Abel

regards / Abel
Scott_Cuff

Hi:

A Webmail to a remote user only goes in the Logs Event tab and has minimal information.

Even the logs on regular mail in the Fortimail provide very little info.

Webmail does appear to send from 127.0.0.1 and my Ip policy (the only one is set as 0.0.0.0 to 0.0.0.0 which I presume includes 127.0.0.1).

Scott 

emnoc
Esteemed Contributor III

I don't know if in a server-mode does it  apply a DKIM on mail sent from the appliance, but have 1> check you have crafted a dkim selector ? 2> ensure the mail header is missing 3> published the  key in DNS & check it via unix dig  ( you have to know the selector that you created  ) ?

 

 

e.g

 

1plus1eq2.com._domainkey

 

 

MACATTACK:Downloads kfelix$ host -t TXT cm._domainkey.flippa.com

cm._domainkey.flippa.com descriptive text "v=DKIM1\; k=rsa\; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCzI/vw8Yd9V1LbsMmL96S9TLd3ewgBDiW+XgY6sqVEpI8gUAiMTE4O0BDIFX0vLuFt33IYQ9jc3noLGSVlsa+SDeCI7sKZG/kXuQJ2nBKH17X8N0QBV7NtUPOdxqorMLoXuO8lq+lXH+a+3xF8pvD2vshxzdKGMkJHyT0mxV0zMwIDAQAB"

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Scott_Cuff

Hi:

 

Thanks but DKIM does work and my selector and DNS are correct as long as the email is initiated from a remote outlook or other client.  Just using the Fortimail webmail does not send DKIM.  This is the question I am asking about.

 

Scott

abelio

Scott Cuff wrote:

Hi:

A Webmail to a remote user only goes in the Logs Event tab and has minimal information.

Even the logs on regular mail in the Fortimail provide very little info.

Webmail does appear to send from 127.0.0.1 and my Ip policy (the only one is set as 0.0.0.0 to 0.0.0.0 which I presume includes 127.0.0.1).

Scott 

Could you please configure an ip policy with source 127.0.0.1 on top of the others, apply your session profile and verify for us your logs that this IP policy is actually matched  your traffic when sending mail with webmail?

Don't forget to check exclusive box at the end.

regards




/ Abel

regards / Abel
Scott_Cuff

Hi:

 

I did check that from mail sent from Outlook the logs show that the Policy ID's are 0:1:20

I am not sure what the 0 is but 1 is my Ip policy and 20 is the Outgoing policy  and this all works.

Webmail's do not show in the History log.   A Webmail login is registered  in the Event Tab (but without Policy ID's) and does not seem to make any entry for mail sent after login.

 

I made an IP policy  at  the top and exclusive for 127.0.0.1 but the email sent from Webmail still does not contain DKIM.  

 

Scott

 

Dirty_Wizard_FTNT

Tested on 5.3.7 server mode.

DKIM signature is applied from webmail when hitting IP Policy with signing enabled.

The IP Policy needs to include 127.0.0.1 as source.

 

Something to consider is encrypted emails will not add the DKIM signature.

Labels
Top Kudoed Authors