Hi all,
I’m running Mail-in-a-Box v77 on Ubuntu 22.04 (Postfix 3.6). One of my domains (programistok.org) sends outbound mail through Amazon SES (eu-central-1). The other domains on the box are unaffected. Routing is per sender domain: sender_dependent_relayhost_maps plus SASL credentials per domain in main.cf. Easy DKIM is enabled in SES, so DMARC passes.
The problem: every message ends up with a broken MiaB DKIM signature. OpenDKIM signs with selector mail (h=From:To:Subject:Date:From), and SES then rewrites the Date header to UTC and replaces Message-ID. That’s documented behaviour; AWS explicitly says not to sign Date/Message-ID. In a test, 17:06:25 +0200 arrived as 15:06:25 +0000. Recipients therefore see dkim=fail for d=programistok.org; s=mail next to dkim=pass for the SES signatures. DMARC is fine, but I’d rather not ship a broken signature on every message.
Why not just disable signing for that domain in OpenDKIM: Postfix picks the relay by envelope sender, but OpenDKIM signs by the From: header. Mail with From: …@programistok.org and a different envelope sender still goes out directly from the box and needs the MiaB signature. Examples are Sieve vacation replies (envelope <>, since sieve_vacation_send_from_recipient is not set) and a couple of addresses I deliberately exclude from the relay.
What I’m planning: strip the MiaB signature only from messages actually being handed to SES, at delivery time:
- A second
smtpclient service inmaster.cf, an exact copy of the defaultsmtp/unixline (same columns), plus two overrides:ses unix ... smtp -o syslog_name=postfix/ses -o smtp_header_checks=pcre:/etc/postfix/ses_strip_miab_dkim - In
main.cf,sender_dependent_default_transport_maps = hash:/etc/postfix/relay_transport:relay@programistok.org DUNNO @programistok.org ses:[email-smtp.eu-central-1.amazonaws.com]:587 /etc/postfix/ses_strip_miab_dkim, which removes only our own signature and leaves any third-party signature on forwarded mail intact:/^DKIM-Signature:(?=.*\bd=programistok\.org;)(?=.*\bs=mail;)/ IGNORE
OpenDKIM, Dovecot and the MiaB config files themselves stay untouched. I’ll test the whole flow in a local Postfix 3.6 container before deploying.
My questions:
- Upgrades: does
setup/start(or anything in daily tasks) rewritemaster.cfwholesale, or only the services it manages? From readingsetup/mail-postfix.shit looks like MiaB only edits its own entries viaeditconf.py -s -w(smtps,submission,authclean). Would an extrasesservice survive an upgrade? In my experience the v77 upgrade kept my relay settings inmain.cfbut reverted my TLS hardening, so I’d like to know what to expect here. (I’ll keep a re-apply script and an alert either way.) - Approach: has anyone else relaying through SES (or another provider that rewrites headers) dealt with this, and solved it differently? Is there something simpler I’m missing, for example making OpenDKIM skip
Datefor one domain only? - Any obvious pitfalls with
sender_dependent_default_transport_mapson a MiaB box? As fsender_dependent_relayhost_maps, which is why the exceptions are repeated asDUNNO.
I know relaying is outside what MiaB supports, so thanks for any pointers.