29. pepsi-stage-dkim-sign¶
Prepend DKIM signatures before delivery.
29.1. Role¶
pepsi-stage-dkim-sign DKIM-signs the message and advances it to a delivery
stage. Separating signing from message construction lets
pepsi-stage-bounce build an unsigned DSN and point its NEXT_STAGE
here, so a generated bounce is signed before it is sent. Reference:
pepsi-stage-dkim-sign(1).
29.2. Features¶
Dual-signature DKIM (RFC 6376): prepends both an RSA-2048 and an Ed25519 (RFC 8463)
DKIM-Signatureheader.Signing domain selection:
SIGNING_DOMAINif set, otherwise the domain of the message’sFrom:header.Body-length tag (optional):
COVER_BODY = noadds anl=tag fixed to the body as signed, so a downstream hop may append a footer without breaking the signature; the signed portion is still fully covered. Defaultyes(nol=).Prepend-only / single write: signatures are added at the top, so existing signatures lower in the message are undisturbed; only the
headerscolumn is rewritten.Fail-open: if no signing domain can be determined or the keys are missing or signing errors, the message is advanced unsigned with a warning.
29.3. Configuration¶
[stage-<name>]: PROGRAM = pepsi-stage-dkim-sign, NEXT_STAGE
(required), COVER_BODY and SIGNING_DOMAIN. Key material and selectors
come from the shared [pepsi] section (KEY_DIR, DKIM_SELECTOR). See
pepsi-stage-dkim-sign(1).
29.4. State¶
Inputs: none from
state(domain fromSIGNING_DOMAINor thefrom_headercolumn; body hash from the loaded message).Outputs: none added; the whole
state, includingstate.dsn, is preserved.
29.5. See also¶
pepsi-stage-bounce, pepsi-stage-relay-to-internet, Supported Features, pepsi-stage-dkim-sign(1).