I’m not using this source ip or not given permission to send mails.(Not included in mx record)
But it seems they have able to send mail using my xxxx.com domain. It seems some how they had my private key. So i need to regenerate dkim keys for that specific domain.
could some one help me to regenerate dkim keys for that domain.
(please note this is not a failure of Mail-in-a-Box server. It seems i have allowed access to my third party team for DNS zone sometime back and from that it seems to be got exposed)
I don’t know. If you’re hosting the DNS on your box, it’s unlikely to do anything untoward, so worth a try. If your DNS is external, you’d need to update at your provider, so the test will involve a little hassle.
Check mailinabox/setup/dkim.sh at main · mail-in-a-box/mailinabox · GitHub lines 56, 61, 62 and 121. I think that should be all that is needed to generate the keys (make a backup of the keys beforehand)
Then run sudo tools/dns_update --force from the mailinabox installation directory.
The ssl/provision API call will not help you. This is for provisioning the let’s encrypt certificates.
I will look into making a button in the Admin Panel for each Domain you have, to reset the DKIM keys that are provisioned. It’s recommended to rotate them every 6 months anyways.
*** Make a Backup of your External DNS and Mail-In-A-Box Server Before attempting to do changes, In case you need to restore***
For the time being till we get a button to regenerate DKIM keys, I have found a solution. But this should be used extremely carefully, because this will regenerate DKIM keys for ALL THE DOMAINS you have in the admin panel. If you host your dns externally, you need to update all related DKIM keys for all domains.
Keep the existing DKIM file as a backup file by renaming (Delete existing DKIM key File)
By doing below, you will lost existing DKIM Keys for all domains which you hosts mail services.