Relaying one domain through Amazon SES: MiaB's DKIM signature always fails (SES rewrites Date). Is a custom master.cf transport safe across upgrades?

Hi all,

I’m running Mail-in-a-Box v77 on Ubuntu 22.04 (Postfix 3.6). One of my domains (programistok.org) sends outbound mail through Amazon SES (eu-central-1). The other domains on the box are unaffected. Routing is per sender domain: sender_dependent_relayhost_maps plus SASL credentials per domain in main.cf. Easy DKIM is enabled in SES, so DMARC passes.

The problem: every message ends up with a broken MiaB DKIM signature. OpenDKIM signs with selector mail (h=From:To:Subject:Date:From), and SES then rewrites the Date header to UTC and replaces Message-ID. That’s documented behaviour; AWS explicitly says not to sign Date/Message-ID. In a test, 17:06:25 +0200 arrived as 15:06:25 +0000. Recipients therefore see dkim=fail for d=programistok.org; s=mail next to dkim=pass for the SES signatures. DMARC is fine, but I’d rather not ship a broken signature on every message.

Why not just disable signing for that domain in OpenDKIM: Postfix picks the relay by envelope sender, but OpenDKIM signs by the From: header. Mail with From: …@programistok.org and a different envelope sender still goes out directly from the box and needs the MiaB signature. Examples are Sieve vacation replies (envelope <>, since sieve_vacation_send_from_recipient is not set) and a couple of addresses I deliberately exclude from the relay.

What I’m planning: strip the MiaB signature only from messages actually being handed to SES, at delivery time:

  1. A second smtp client service in master.cf, an exact copy of the default smtp/unix line (same columns), plus two overrides:
    ses unix ... smtp
      -o syslog_name=postfix/ses
      -o smtp_header_checks=pcre:/etc/postfix/ses_strip_miab_dkim
    
  2. In main.cf, sender_dependent_default_transport_maps = hash:/etc/postfix/relay_transport:
    relay@programistok.org  DUNNO
    @programistok.org       ses:[email-smtp.eu-central-1.amazonaws.com]:587
    
  3. /etc/postfix/ses_strip_miab_dkim, which removes only our own signature and leaves any third-party signature on forwarded mail intact:
    /^DKIM-Signature:(?=.*\bd=programistok\.org;)(?=.*\bs=mail;)/ IGNORE
    

OpenDKIM, Dovecot and the MiaB config files themselves stay untouched. I’ll test the whole flow in a local Postfix 3.6 container before deploying.

My questions:

  1. Upgrades: does setup/start (or anything in daily tasks) rewrite master.cf wholesale, or only the services it manages? From reading setup/mail-postfix.sh it looks like MiaB only edits its own entries via editconf.py -s -w (smtps, submission, authclean). Would an extra ses service survive an upgrade? In my experience the v77 upgrade kept my relay settings in main.cf but reverted my TLS hardening, so I’d like to know what to expect here. (I’ll keep a re-apply script and an alert either way.)
  2. Approach: has anyone else relaying through SES (or another provider that rewrites headers) dealt with this, and solved it differently? Is there something simpler I’m missing, for example making OpenDKIM skip Date for one domain only?
  3. Any obvious pitfalls with sender_dependent_default_transport_maps on a MiaB box? As f sender_dependent_relayhost_maps, which is why the exceptions are repeated as DUNNO.

I know relaying is outside what MiaB supports, so thanks for any pointers.