<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.hobby.nl/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=2A05%3AF080%3A0%3A300%3AB848%3A81C0%3A7F18%3AAA86</id>
	<title>Hobbynet Admin Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.hobby.nl/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=2A05%3AF080%3A0%3A300%3AB848%3A81C0%3A7F18%3AAA86"/>
	<link rel="alternate" type="text/html" href="https://wiki.hobby.nl/index.php/Special:Contributions/2A05:F080:0:300:B848:81C0:7F18:AA86"/>
	<updated>2026-05-14T14:21:14Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.40.1</generator>
	<entry>
		<id>https://wiki.hobby.nl/index.php?title=DKIM&amp;diff=78342</id>
		<title>DKIM</title>
		<link rel="alternate" type="text/html" href="https://wiki.hobby.nl/index.php?title=DKIM&amp;diff=78342"/>
		<updated>2020-04-05T11:07:30Z</updated>

		<summary type="html">&lt;p&gt;2A05:F080:0:300:B848:81C0:7F18:AA86: /* Key maken */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;===Inleiding===&lt;br /&gt;
Om minder snel als spammer te worden aangemerkt kan de mail &amp;quot;ge-signed&amp;quot; worden. Hiervoor moet OpenDKIM geinstalleerd worden en een kleine aanpassing aan de postfix configuratie gemaakt worden.&lt;br /&gt;
===Installatie===&lt;br /&gt;
Gebruik zoals altijd apt-get of aptitude om een package te instaleren.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
apt-get install opendkim opendkim-tools&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
===Configuratie===&lt;br /&gt;
De configuratie van OpenDKIM staat in /etc/opendkim.conf en dient er als volgt ui te zien:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# This is a basic configuration that can easily be adapted to suit a standard&lt;br /&gt;
# installation. For more advanced options, see opendkim.conf(5) and/or&lt;br /&gt;
# /usr/share/doc/opendkim/examples/opendkim.conf.sample.&lt;br /&gt;
#&lt;br /&gt;
#Domain                  example.com&lt;br /&gt;
#KeyFile                 /etc/opendkim/201205.private&lt;br /&gt;
#Selector                201205&lt;br /&gt;
#&lt;br /&gt;
# Commonly-used options&lt;br /&gt;
Canonicalization        relaxed/simple&lt;br /&gt;
Mode                    sv&lt;br /&gt;
SubDomains              yes&lt;br /&gt;
# Log to syslog&lt;br /&gt;
Syslog                  yes&lt;br /&gt;
LogWhy                  yes&lt;br /&gt;
# Required to use local socket with MTAs that access the socket as a non-&lt;br /&gt;
# privileged user (e.g. Postfix)&lt;br /&gt;
UMask                   022&lt;br /&gt;
UserID                  opendkim:opendkim&lt;br /&gt;
#&lt;br /&gt;
KeyTable                /etc/opendkim/KeyTable&lt;br /&gt;
SigningTable            /etc/opendkim/SigningTable&lt;br /&gt;
ExternalIgnoreList      /etc/opendkim/TrustedHosts&lt;br /&gt;
InternalHosts           /etc/opendkim/TrustedHosts&lt;br /&gt;
#&lt;br /&gt;
Socket                  inet:8891@localhost&lt;br /&gt;
#EOF&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Voor uitleg over de diverse parameters, kijk bijvoorbeeld op [https://www.digitalocean.com/community/tutorials/how-to-install-and-configure-dkim-with-postfix-on-debian-wheezy deze site].&lt;br /&gt;
&lt;br /&gt;
===Directory structuur===&lt;br /&gt;
Er moet een directory structuur gemaakt worden om trusted hosts, key tables, signing tables en crypto keys op te slaan. Maak daartoe /etc/opendkim aan met daarin de volgende files en directory: &lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@mail-lb1:/etc/opendkim# ls -l&lt;br /&gt;
total 16&lt;br /&gt;
-rw-r--r-- 1 root root   90 May 25 14:23 KeyTable&lt;br /&gt;
-rw-r--r-- 1 root root   38 May 25 14:24 SigningTable&lt;br /&gt;
-rw-r--r-- 1 root root  151 May 28 22:42 TrustedHosts&lt;br /&gt;
drwxr-xr-x 3 root root 4096 May 25 14:26 keys&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
In de directory komen de keys van de domeinen te staan. &lt;br /&gt;
===Key maken===&lt;br /&gt;
Er is een script die maakt de keys aan en voegt de key toe aan de juiste tabellen&lt;br /&gt;
   /usr/local/hobbynet/bin/maakopendkim.sh &#039;&#039;&#039;domeinnaam&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Als je dit script uitvoerd zet de keys op beide servers update de tabellen en herstart dkim na afloop verteld hij ook wat je in dns moet zetten&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@mail-lb1:/etc/opendkim# /usr/local/hobbynet/bin/maakopendkim.sh joomla-dev.hobby.nl&lt;br /&gt;
&lt;br /&gt;
Zet dit in de DNS zone voor: joomla-dev.hobby.nl&lt;br /&gt;
&lt;br /&gt;
default._domainkey.joomla-dev.hobby.nl. IN      TXT     ( &amp;quot;v=DKIM1; h=sha256; k=rsa; s=email; &amp;quot;&lt;br /&gt;
          &amp;quot;p=MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAw2jWysEKHJVxB+Mz2/94YREk2CZ4iqUwsLtGwRQPraMnOQNsZaC0Ze4YtSJgtmaIdqqnrgkvmWQoG4lcHcJ9a4lyTh//BO1eNGVtTWfAl6L1s4Y647crTnDobqDJKl6oAW8G9pA0clnwLoWxhIEVkd1KHPcp4YGzKR4VywYVpc8bU+Qim2yLwlf7AtB67lOT43H53vBjtAntm4&amp;quot;&lt;br /&gt;
          &amp;quot;8aDZr3oN9K/LmYUw66n4BjcJQ8E9jdF2/HIVLPu2tOCP7I8LPAUjrW/v9b9v4P2aC6olxK93IcldGjrFd/S79nRvWBrOkPPj65EsQNLx6hWO97z6VqQD9pP4MinGpSOQ3nC3minRxR4qu9o45T8MditxO8ojjbF1sHxadRZPqa140E7Zxo5qEhhsb+e3rQgGYvina/LGxmef7C94e5/HFcgepN6WySMrFWJh1HXeBydScboX/j3gL7yNty&amp;quot;&lt;br /&gt;
          &amp;quot;FMg4bwthQB1TwCEsVpviQjDBo02nd3QtBupUWzcWuR61d6oBgoOCqUnS8uLTyDdo5lXUrjl6Kduja6tolEbJt5JWCviKNPobINqfKr4R4HVpBo+koLMqyzRxswomzYXort/YWSZJmkXKVeMKGW89GZhz5qRr9rOJUFQc/IdTy8C4bdaDV/8hOX0wtrPPEzT4FU5mb9oNLntHy1wm7PKZR0SNdoUylSS+vYcCAwEAAQ==&amp;quot; )  ; ----- DKIM key default for joomla-dev.hobby.nl&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===De Postfix kant===&lt;br /&gt;
Tevens moet in /etc/default/opendkim alles uitgecommentarieerd worden en deze regel toegevoegd worden:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
SOCKET=&amp;quot;inet:8891@localhost&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Dit socket dient aan Postfix bekend te worden gemaakt. Voeg de volgende regels aan /etc/postfix/main.cf toe:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# DKIM&lt;br /&gt;
milter_default_action = accept&lt;br /&gt;
milter_protocol = 2&lt;br /&gt;
smtpd_milters = inet:localhost:8891&lt;br /&gt;
non_smtpd_milters = inet:localhost:8891&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Hierdoor controleert en zet Postfix nu ook dkim handtekeningen. Vergeet niet Postfix te herstarten.&lt;br /&gt;
&lt;br /&gt;
===Testen===&lt;br /&gt;
De configuratie kan worden getest door een lege mail te sturen naar &#039;&#039;&#039;check-auth@verifier.port25.com&#039;&#039;&#039;. Als alles werkt zal in de reply &#039;&#039;&#039;DKIM check: pass&#039;&#039;&#039; staan onder &#039;&#039;&#039;Summary of Results&#039;&#039;&#039;. Voor de geïnteresseerde is het hele bericht opgenomen. &lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
==========================================================&lt;br /&gt;
Summary of Results&lt;br /&gt;
==========================================================&lt;br /&gt;
SPF check:          pass&lt;br /&gt;
&amp;quot;iprev&amp;quot; check:      pass&lt;br /&gt;
DKIM check:         pass&lt;br /&gt;
SpamAssassin check: ham&lt;br /&gt;
&lt;br /&gt;
==========================================================&lt;br /&gt;
Details:&lt;br /&gt;
==========================================================&lt;br /&gt;
&lt;br /&gt;
HELO hostname:  mail-lb1.hobby.nl&lt;br /&gt;
Source IP:      212.72.224.72&lt;br /&gt;
mail-from:      rootmail@hobby.nl&lt;br /&gt;
&lt;br /&gt;
----------------------------------------------------------&lt;br /&gt;
SPF check details:&lt;br /&gt;
----------------------------------------------------------&lt;br /&gt;
Result:         pass&lt;br /&gt;
ID(s) verified: smtp.mailfrom=rootmail@hobby.nl&lt;br /&gt;
&lt;br /&gt;
DNS record(s):&lt;br /&gt;
    hobby.nl. 60 IN TXT &amp;quot;v=spf1 ip4:212.72.224.0/21 ip4:95.97.35.96/29 ip4:80.253.112.0/24 ip4:94.232.160.0/24 ip6:2a02:968::/32 -all&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----------------------------------------------------------&lt;br /&gt;
&amp;quot;iprev&amp;quot; check details:&lt;br /&gt;
----------------------------------------------------------&lt;br /&gt;
Result:         pass (matches mail-lb1.hobby.nl)&lt;br /&gt;
ID(s) verified: policy.iprev=212.72.224.72&lt;br /&gt;
&lt;br /&gt;
DNS record(s):&lt;br /&gt;
    72.224.72.212.in-addr.arpa. 60 IN PTR mail-lb1.hobby.nl.&lt;br /&gt;
    mail-lb1.hobby.nl. 60 IN A 212.72.224.72&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----------------------------------------------------------&lt;br /&gt;
DKIM check details:&lt;br /&gt;
----------------------------------------------------------&lt;br /&gt;
Result:         pass (matches From: rootmail@hobby.nl)&lt;br /&gt;
ID(s) verified: header.d=hobby.nl&lt;br /&gt;
&lt;br /&gt;
Canonicalized Headers:&lt;br /&gt;
    reply-to:rootmail@hobby.nl&#039;0D&#039;&#039;0A&#039;&lt;br /&gt;
    to:check-auth@verifier.port25.com&#039;0D&#039;&#039;0A&#039;&lt;br /&gt;
    from:Hobbynet&#039;20&#039;rootmaill&#039;20&#039;&amp;lt;rootmail@hobby.nl&amp;gt;&#039;0D&#039;&#039;0A&#039;&lt;br /&gt;
    subject:test&#039;0D&#039;&#039;0A&#039;&lt;br /&gt;
    date:Thu,&#039;20&#039;31&#039;20&#039;May&#039;20&#039;2018&#039;20&#039;21:48:24&#039;20&#039;+0200&#039;0D&#039;&#039;0A&#039;&lt;br /&gt;
    dkim-signature:v=1;&#039;20&#039;a=rsa-sha256;&#039;20&#039;c=relaxed/simple;&#039;20&#039;d=hobby.nl;&#039;20&#039;s=default;&#039;20&#039;t=1527796105;&#039;20&#039;bh=frcCV1k9oG9oKj3dpUqdJg1PxRT2RSN/XKdLCPjaYaY=;&#039;20&#039;h=Reply-To:To:From:Subject:Date;&#039;20&#039;b=&lt;br /&gt;
&lt;br /&gt;
Canonicalized Body:&lt;br /&gt;
    &#039;0D&#039;&#039;0A&#039;&lt;br /&gt;
    &lt;br /&gt;
&lt;br /&gt;
DNS record(s):&lt;br /&gt;
    default._domainkey.hobby.nl. 60 IN TXT &amp;quot;v=DKIM1; k=rsa; s=email; p=MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAyHQygiGyUV+o4WTsNIbxfYPyADNedPojfVfn2YrCZJ6WFhBi6RNKKJndqE+VGgtScSI1fkLRCyquVPTGICUAnUbUQL2NbGQNyo0T8wBJy5QTarir10IMue/2QtjaPnDkwa4m35Bl9YKm4SgeaTd7A/OWXsO2BAgCYfiAHsFvK6e6u4zwcD1ZlGH9bSrgm5x6ucHkROq9aV0R0Pr/+SGkT+9Zs1L/TqbX0OvoKmG+raffHVghG8USo1EVWzFSi7gURqP6C8f9HW4HfLnR203C8uJMHSzBvPv5PbM+kc/QTu1AE478a6aZyaUsEhHQQx7OV08crT6UsdyUHQlQpgl8aR+MwAyrEH54AAPzYjfN5KNsZ35flf2/Yj6X5KtGeG0ZVMR2cew1z3SKTFXg+rq+TWF3EqhiD3fzTypSYk5nhKpKpMYtoU7JytF4Xw02fyJpbiVdAGsLqibM+rY+4qp+C/t1HKHVavGePdg5iBE/Y+lOqG6dJvXpWe7JjEz7HfZOz69XN0ryL5/JUzfCpf7lvyJ3LKET4OuBbSwypzNeDX+DaAHb4qdwNFJGq8H0DjFFFagmPQSeHZdX7qTtIiOSbogFXab2Yz9Yw38GedKk9UQPSdCLqdzeFEZWuTXDn/NdRA7PqWuAUxoe68O57Esz4dnyLqB1Xrs74IzTRpLhiSECAwEAAQ==&amp;quot;&lt;br /&gt;
&lt;br /&gt;
Public key used for verification: default._domainkey.hobby.nl (4096 bits)&lt;br /&gt;
&lt;br /&gt;
NOTE: DKIM checking has been performed based on the latest DKIM specs&lt;br /&gt;
(RFC 4871 or draft-ietf-dkim-base-10) and verification may fail for&lt;br /&gt;
older versions.  If you are using Port25&#039;s PowerMTA, you need to use&lt;br /&gt;
version 3.2r11 or later to get a compatible version of DKIM.&lt;br /&gt;
&lt;br /&gt;
----------------------------------------------------------&lt;br /&gt;
SpamAssassin check details:&lt;br /&gt;
----------------------------------------------------------&lt;br /&gt;
SpamAssassin v3.4.0 (2014-02-07)&lt;br /&gt;
&lt;br /&gt;
Result:         ham (-2.0 points, 5.0 required)&lt;br /&gt;
&lt;br /&gt;
 pts rule name              description&lt;br /&gt;
---- ---------------------- --------------------------------------------------&lt;br /&gt;
-0.0 RCVD_IN_DNSWL_NONE     RBL: Sender listed at http://www.dnswl.org/, no&lt;br /&gt;
                            trust&lt;br /&gt;
                            [212.72.224.72 listed in list.dnswl.org]&lt;br /&gt;
-0.0 SPF_PASS               SPF: sender matches SPF record&lt;br /&gt;
-1.9 BAYES_00               BODY: Bayes spam probability is 0 to 1%&lt;br /&gt;
                            [score: 0.0000]&lt;br /&gt;
-0.1 DKIM_VALID_AU          Message has a valid DKIM or DK signature from author&#039;s&lt;br /&gt;
                            domain&lt;br /&gt;
 0.1 DKIM_SIGNED            Message has a DKIM or DK signature, not necessarily valid&lt;br /&gt;
-0.1 DKIM_VALID             Message has at least one valid DKIM or DK signature&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==============================================================&lt;br /&gt;
Explanation of the possible results (based on RFCs 7601, 7208)&lt;br /&gt;
==============================================================&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
DKIM Results&lt;br /&gt;
============&lt;br /&gt;
&lt;br /&gt;
none:  The message was not signed.&lt;br /&gt;
&lt;br /&gt;
pass:  The message was signed, the signature or signatures were&lt;br /&gt;
    acceptable to the ADMD, and the signature(s) passed verification&lt;br /&gt;
    tests.&lt;br /&gt;
&lt;br /&gt;
fail:  The message was signed and the signature or signatures were&lt;br /&gt;
    acceptable to the ADMD, but they failed the verification test(s).&lt;br /&gt;
&lt;br /&gt;
policy:  The message was signed, but some aspect of the signature or&lt;br /&gt;
    signatures was not acceptable to the ADMD.&lt;br /&gt;
&lt;br /&gt;
neutral:  The message was signed, but the signature or signatures&lt;br /&gt;
    contained syntax errors or were not otherwise able to be&lt;br /&gt;
    processed.  This result is also used for other failures not&lt;br /&gt;
    covered elsewhere in this list.&lt;br /&gt;
&lt;br /&gt;
temperror:  The message could not be verified due to some error that&lt;br /&gt;
    is likely transient in nature, such as a temporary inability to&lt;br /&gt;
    retrieve a public key.  A later attempt may produce a final&lt;br /&gt;
    result.&lt;br /&gt;
&lt;br /&gt;
permerror:  The message could not be verified due to some error that&lt;br /&gt;
    is unrecoverable, such as a required header field being absent.  A&lt;br /&gt;
    later attempt is unlikely to produce a final result.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
SPF Results&lt;br /&gt;
===========&lt;br /&gt;
&lt;br /&gt;
none:  Either (a) no syntactically valid DNS domain name was extracted from&lt;br /&gt;
    the SMTP session that could be used as the one to be authorized, or&lt;br /&gt;
    (b) no SPF records were retrieved from the DNS.&lt;br /&gt;
&lt;br /&gt;
neutral:  The ADMD has explicitly stated that it is not asserting whether&lt;br /&gt;
    the IP address is authorized.&lt;br /&gt;
&lt;br /&gt;
pass:  An explicit statement that the client is authorized to inject mail&lt;br /&gt;
    with the given identity.&lt;br /&gt;
&lt;br /&gt;
fail:  An explicit statement that the client is not authorized to use the&lt;br /&gt;
    domain in the given identity.&lt;br /&gt;
&lt;br /&gt;
softfail:  A weak statement by the publishing ADMD that the host is probably&lt;br /&gt;
    not authorized.  It has not published a stronger, more definitive policy&lt;br /&gt;
    that results in a &amp;quot;fail&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
temperror:  The SPF verifier encountered a transient (generally DNS) error&lt;br /&gt;
    while performing the check.  A later retry may succeed without further&lt;br /&gt;
    DNS operator action.&lt;br /&gt;
&lt;br /&gt;
permerror: The domain&#039;s published records could not be correctly interpreted.&lt;br /&gt;
    This signals an error condition that definitely requires DNS operator&lt;br /&gt;
    intervention to be resolved.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;quot;iprev&amp;quot; Results&lt;br /&gt;
===============&lt;br /&gt;
&lt;br /&gt;
pass:  The DNS evaluation succeeded, i.e., the &amp;quot;reverse&amp;quot; and&lt;br /&gt;
    &amp;quot;forward&amp;quot; lookup results were returned and were in agreement.&lt;br /&gt;
&lt;br /&gt;
fail:  The DNS evaluation failed.  In particular, the &amp;quot;reverse&amp;quot; and&lt;br /&gt;
    &amp;quot;forward&amp;quot; lookups each produced results, but they were not in&lt;br /&gt;
    agreement, or the &amp;quot;forward&amp;quot; query completed but produced no&lt;br /&gt;
    result, e.g., a DNS RCODE of 3, commonly known as NXDOMAIN, or an&lt;br /&gt;
    RCODE of 0 (NOERROR) in a reply containing no answers, was&lt;br /&gt;
    returned.&lt;br /&gt;
&lt;br /&gt;
temperror:  The DNS evaluation could not be completed due to some&lt;br /&gt;
    error that is likely transient in nature, such as a temporary DNS&lt;br /&gt;
    error, e.g., a DNS RCODE of 2, commonly known as SERVFAIL, or&lt;br /&gt;
    other error condition resulted.  A later attempt may produce a&lt;br /&gt;
    final result.&lt;br /&gt;
&lt;br /&gt;
permerror:  The DNS evaluation could not be completed because no PTR&lt;br /&gt;
    data are published for the connecting IP address, e.g., a DNS&lt;br /&gt;
    RCODE of 3, commonly known as NXDOMAIN, or an RCODE of 0 (NOERROR)&lt;br /&gt;
    in a reply containing no answers, was returned.  This prevented&lt;br /&gt;
    completion of the evaluation.  A later attempt is unlikely to&lt;br /&gt;
    produce a final result.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==========================================================&lt;br /&gt;
Original Email&lt;br /&gt;
==========================================================&lt;br /&gt;
&lt;br /&gt;
Return-Path: &amp;lt;rootmail@hobby.nl&amp;gt;&lt;br /&gt;
Received: from mail-lb1.hobby.nl (212.72.224.72) by verifier.port25.com id h218om2e8s48 for &amp;lt;check-auth@verifier.port25.com&amp;gt;; Thu, 31 May 2018 19:48:27 +0000 (envelope-from &amp;lt;rootmail@hobby.nl&amp;gt;)&lt;br /&gt;
Authentication-Results: verifier.port25.com; spf=pass  smtp.mailfrom=rootmail@hobby.nl;&lt;br /&gt;
 iprev=pass (matches mail-lb1.hobby.nl)  policy.iprev=212.72.224.72;&lt;br /&gt;
 dkim=pass (matches From: rootmail@hobby.nl)  header.d=hobby.nl&lt;br /&gt;
Received: from localhost (localhost [127.0.0.1])&lt;br /&gt;
	by mail-lb1.hobby.nl (Postfix) with ESMTP id 8396E5FDEA&lt;br /&gt;
	for &amp;lt;check-auth@verifier.port25.com&amp;gt;; Thu, 31 May 2018 21:48:25 +0200 (CEST)&lt;br /&gt;
X-Virus-Scanned: Debian amavisd-new at mail-lb1.hobby.nl&lt;br /&gt;
Received: from mail-lb1.hobby.nl ([127.0.0.1])&lt;br /&gt;
	by localhost (mail-lb1.hobby.nl [127.0.0.1]) (amavisd-new, port 10024)&lt;br /&gt;
	with ESMTP id bnAxJuumS9FK for &amp;lt;check-auth@verifier.port25.com&amp;gt;;&lt;br /&gt;
	Thu, 31 May 2018 21:48:25 +0200 (CEST)&lt;br /&gt;
Received: from [192.168.10.12] (vandenbussche.xs4all.nl [83.163.218.172])&lt;br /&gt;
	(using TLSv1 with cipher ECDHE-RSA-AES128-SHA (128/128 bits))&lt;br /&gt;
	(No client certificate requested)&lt;br /&gt;
	(Authenticated sender: egbert@vandenbussche.nl)&lt;br /&gt;
	by mail-lb1.hobby.nl (Postfix) with ESMTPSA id 51FE55FDE6&lt;br /&gt;
	for &amp;lt;check-auth@verifier.port25.com&amp;gt;; Thu, 31 May 2018 21:48:25 +0200 (CEST)&lt;br /&gt;
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=hobby.nl; s=default;&lt;br /&gt;
	t=1527796105; bh=frcCV1k9oG9oKj3dpUqdJg1PxRT2RSN/XKdLCPjaYaY=;&lt;br /&gt;
	h=Reply-To:To:From:Subject:Date;&lt;br /&gt;
	b=allKIIWMLMVr0ufrCeIkA8T7VF6xZ9PpPDEG80vqoQraDkwa8FAal+ZXhK/Y/nwtO&lt;br /&gt;
	 XYzhEZmOHSYtvTplFppuvXCsbK2q/ZYf881CounLX/w+Ko0ZNIgJwsOz7WX7MJLDXS&lt;br /&gt;
	 cp13/hRVzNYv0LBsI1sz6cXKkNhVxWEShaIjsSW84bQgAAznR0zG9ZYLuVEXm614T0&lt;br /&gt;
	 cz56At+ONbF/8wqBy3rYRBjJ+66xvajO5DfKX94zJErCpvyoiTYCtO5uf0H3sIsiDs&lt;br /&gt;
	 l7a7IUV3Ituzw0+VNpnRP1J3cNxI7j51EGaoUI1w501cCV6f0wC/qbXd9UVHBAl78g&lt;br /&gt;
	 84j+gS4ImtTe9hR3llRnW+2TfuWradddBjUSkX1UiZDORvMkZM+J2pCgFYxU1GXoR+&lt;br /&gt;
	 GHnDPYqW9KDfuVAHUYU6iZ4eDrijS/Y5OBhix1mAX4/XkYaagpbXD9tr/43nNGV3YU&lt;br /&gt;
	 O8S91tFCgik86DfD5b98lxrr61KHb0X/brYF9l8oBvG9L9nuK0g9r90NeLwhmn88dm&lt;br /&gt;
	 Ll4wN0yIHI3yxEQtli6CdZ4H6gJczv6CRp74U/oNyO8PWIm7Nu4grCtWNPXuOzcHjr&lt;br /&gt;
	 FsGPJun8WFVjwVPeKoEOgUTI27g4nfbHkXQEBb9ykQVvVpe44RXbruS81rfKoPThAw&lt;br /&gt;
	 AU/un1L18tPKxUU+jtT2m2hI=&lt;br /&gt;
Reply-To: rootmail@hobby.nl&lt;br /&gt;
To: check-auth@verifier.port25.com&lt;br /&gt;
From: Hobbynet rootmaill &amp;lt;rootmail@hobby.nl&amp;gt;&lt;br /&gt;
Subject: test&lt;br /&gt;
Openpgp: preference=signencrypt&lt;br /&gt;
Autocrypt: addr=rootmail@hobby.nl; prefer-encrypt=mutual; keydata=&lt;br /&gt;
 xsFNBFZ2htYBEADt6zlAySAIrmfb6mRkAPuekeaAM6jIw6n4vdcpGdYi1fL63uZypoh61Ra7&lt;br /&gt;
 lF8SGs3uNhR6EyfJt/54Wsfami+KE4x5nd0dwPAWEwMaruxwKHBmGU1X/895EoRa3aa6PsEc&lt;br /&gt;
 SGyfJplaCscyTneEdsrhtdqKdJi/be8YunhAuYfu1rEaT8FU+hz1itWJJ/YZycscSA8Cb91d&lt;br /&gt;
 w8dUkJamdK0KtaHXOq0pZcJPICtzd0zQIYuouJM1nAjPqQ6GYWu+TebJorWlrHKIzX9WCE1D&lt;br /&gt;
 4wxktMXC+CCwRrV7YLV48ouMuqFejEYvBPjdiIqfxI+vw3bYmtRg0aQ0i3cvadnq6rYS1P6Y&lt;br /&gt;
 nAKk3U1v1Pr83FPUCgTFTpQqHbNJiRDa3tFkVFrY7YtnW4+iHJ8gT2HLOkzpxq/jkhf6gwSQ&lt;br /&gt;
 GgzAf7hepWBUWpKsd501ezVSoza3WQ4laIqvUaYcMGpdeY2vkHASuBulF/QyOk25PBQGVMjL&lt;br /&gt;
 IKovZKIkCp3ghXmYeNjMvtIih3Zh3edH4eekVpP4tgFkdddwguA/yEYYyvFv8KGBvBrQCMzF&lt;br /&gt;
 ghhDRJ6cZL1ewEwuVkGH9qXlM/Gfw4NUo/APuGbbU2PXSxzdxOxbJX2XuRripIsVTVwWKAeb&lt;br /&gt;
 SAitSSFP8B5talGvV3pKooYxAMNa27LRkoZbMjSOVFJ2yeIUHQARAQABzSBFZ2JlcnQgPGVn&lt;br /&gt;
 YmVydEB2YW5kZW5idXNzY2hlLm5sPsLBggQTAQgALAIbIwUJCWYBgAcLCQgHAwIBBhUIAgkK&lt;br /&gt;
 CwQWAgMBAh4BAheABQJWdoj5AhkBAAoJEElE8PvYS2x3wFYP/jy1Ym+6oQDPuHNauYnujpe5&lt;br /&gt;
 DyZOUrPTHdDqg+HjSXzoozeQGeKpIeAZj7ZXSpfGr4mPaPn8gaWxr6ibQAkVYvTZ4MttoqFo&lt;br /&gt;
 cT3ePbUGHnagNcwAZJlcoNJQ6S92YYVWryFn0F8JMUcnQzUaJyUOIaf5pcdJcbA6bPBcMa8X&lt;br /&gt;
 oHSEyD48Dauir7QpsDTurfTooRBZrlLXMkQCeO+FR2R+2WXt7JxQEv1tDZ6xCS/CTMdibszn&lt;br /&gt;
 fQqlEMj6qNdLh7ymM8umqFlfPx8xRTom8ClkhJryDpV3yYiz380aOt3SCzee68GOwXyM98+P&lt;br /&gt;
 GD9QSzlhxjh6GF5bhW4jEH5uLByjIUQNDIBDvuqSIWWnBE39zoGqvlAlO9ZOtYaHprCREBkF&lt;br /&gt;
 IQHiHqOLMkzBHkHJOrqmROkDXpUSeso1rQZEo/13axZyu4JCgHEGONhCDrzZWjK2ASPQZzjL&lt;br /&gt;
 dAKkuvfIJlwS0yctYWcaK6ttPLyteujWjHbfvJRT6BRLlr0YnmSZs86xWpYnXMrG9xa886Us&lt;br /&gt;
 kswQd7c2QZuBpLgHW3KzrFvCd/LKp3UvPiVUigK6Xgoi7xwwxfv8O4EeZYO2U35w5SPlg+Mz&lt;br /&gt;
 FEJVH2whxboMrHZRhLtyPKY0+qqkLP2LxphUAeNRWNOJIXiazTq1/4Y5dVK1zIq6gg2dBMmH&lt;br /&gt;
 PHx8fQAnhphZzsFNBFZ2htYBEAC7NDbfwBKMD8VRlVUxIds4+0SGsRUhwHQJrU0Tn8vzFiRS&lt;br /&gt;
 GBtDuOdAPyt8GDrjh2c2PKno9piQnbojqKGJ0HvGoHzfm9axb0S4CPgGfcIrSjyQIu4+kpCj&lt;br /&gt;
 tatSaxtuvqqpxNBx9ylfubJgTKW96m8K8twbXc6QczMsd6zSt4U5ER8EWrlT1JB+mW+hNuQW&lt;br /&gt;
 4VQ1A6f0JRQqXOA1b23yNW621CfT9r9t4OpDug9vWyGXyQjjLoiMRsGVH5B/37UXn2BS14wh&lt;br /&gt;
 2xLj+eh9V1pN4S1IZVv/k0EdRwn9VC/bSGgTbk6P6oOM7LrV+BM7yQHoFOO5HPb2jJB+ynVu&lt;br /&gt;
 K4/n0Xe/Zcfp2OPAm9qn5Z0lkTSHRxvCMWxxNoAgirzj/KdNnuDVU7SdRulynIcczqj68adV&lt;br /&gt;
 uEyPeu1mwhOTku7eQnlFmGhkD5oJfg/IPdb7OmnpWsFPfyowG/nR7oPAFVkoNfRRqtUpHIM4&lt;br /&gt;
 k+2Xm/lWxYHzlzVF9SzbLWKs3/J9tyVb7xNAlr8gcbwgO8bOwWUiAG6hSMD1yLdox92seRPY&lt;br /&gt;
 mnhOC6PCG3KKqCH7wBZ84Ez0BDqYDqSzq4/PlCnJrMk3ewb/fuGiMF7kgYHThvdZUeyRgUoY&lt;br /&gt;
 yG7i3R3XRFDUiN5m7SyuRUUdgHwznb2e8Pf/IMYtTZh737bgM+mWc/YlJq+cmQARAQABwsFl&lt;br /&gt;
 BBgBCAAPBQJWdobWAhsMBQkJZgGAAAoJEElE8PvYS2x3Ad0QAN/WS9Mc0MdhJi7fqhq5dU4X&lt;br /&gt;
 QfviUMA5CkWboNiOG57OR1C0a4XJcFCDcgmsYRhMYDj4qw7M+z3fcjFJnEwqHHoIhzsvGbDs&lt;br /&gt;
 Dra8QkP188tx+Uzf4wMnEVCVzOuL5ji36OlxegF5wjj5CTtso237hhcI82+xAnqXteA5pJMw&lt;br /&gt;
 DunRmhEkjpJjxkUtr4vyOSzGBmMP3sWGbq0uVbWacxggb1r56+uKrQULVEnCa4P64d8RPKn7&lt;br /&gt;
 Dsn/Pqf7n+nLevBertj5roQNceXeGIpu0k45wVFUtCA9Rc1Y6myNs0aq8Cw5LKTLemI+uT4y&lt;br /&gt;
 Okky89vroZqG/XetHAXxjZGm+kyMbu3ThvIzOSb5+hTfWcTa8zybUvujkfiejfhRDZ9GWjXS&lt;br /&gt;
 iK20nZ8d2WwTqPDOMySozXFUJoT6TqTJ/I7m9vJj2mz+xPRLHaAVVKF7rMP8Gw+6g9uWbHs1&lt;br /&gt;
 SXAZH/CgQTAJwQ+FxWC657Q+bjg11lmjCHpDMxxFnIdqYiIaKjocQzI2SP67Yr94W0trumOR&lt;br /&gt;
 fZm3nietLoSVVkak0z+SBJZ4/S+XbkDmLnUDG3GJq/QCXFAFVv02VS76gvVYaxFuVWOUIuXf&lt;br /&gt;
 SkWKoa6vs12Cx30Hp/BfdftCHH6IuhzXspKK+br9CqDrRZcHzMB42/QPYcDa/BZBzudBXsZd&lt;br /&gt;
 M+CrfDxPMyd7&lt;br /&gt;
Organization: HCC!Hobbynet&lt;br /&gt;
Message-ID: &amp;lt;bc4cc04a-de4c-54f7-37c4-ffb6f589fb4b@hobby.nl&amp;gt;&lt;br /&gt;
Date: Thu, 31 May 2018 21:48:24 +0200&lt;br /&gt;
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101&lt;br /&gt;
 Thunderbird/52.8.0&lt;br /&gt;
MIME-Version: 1.0&lt;br /&gt;
Content-Type: text/plain; charset=utf-8&lt;br /&gt;
Content-Language: nl&lt;br /&gt;
Content-Transfer-Encoding: 7bit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>2A05:F080:0:300:B848:81C0:7F18:AA86</name></author>
	</entry>
	<entry>
		<id>https://wiki.hobby.nl/index.php?title=DKIM&amp;diff=78340</id>
		<title>DKIM</title>
		<link rel="alternate" type="text/html" href="https://wiki.hobby.nl/index.php?title=DKIM&amp;diff=78340"/>
		<updated>2020-04-05T11:03:39Z</updated>

		<summary type="html">&lt;p&gt;2A05:F080:0:300:B848:81C0:7F18:AA86: /* De Postfix kant */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;===Inleiding===&lt;br /&gt;
Om minder snel als spammer te worden aangemerkt kan de mail &amp;quot;ge-signed&amp;quot; worden. Hiervoor moet OpenDKIM geinstalleerd worden en een kleine aanpassing aan de postfix configuratie gemaakt worden.&lt;br /&gt;
===Installatie===&lt;br /&gt;
Gebruik zoals altijd apt-get of aptitude om een package te instaleren.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
apt-get install opendkim opendkim-tools&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
===Configuratie===&lt;br /&gt;
De configuratie van OpenDKIM staat in /etc/opendkim.conf en dient er als volgt ui te zien:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# This is a basic configuration that can easily be adapted to suit a standard&lt;br /&gt;
# installation. For more advanced options, see opendkim.conf(5) and/or&lt;br /&gt;
# /usr/share/doc/opendkim/examples/opendkim.conf.sample.&lt;br /&gt;
#&lt;br /&gt;
#Domain                  example.com&lt;br /&gt;
#KeyFile                 /etc/opendkim/201205.private&lt;br /&gt;
#Selector                201205&lt;br /&gt;
#&lt;br /&gt;
# Commonly-used options&lt;br /&gt;
Canonicalization        relaxed/simple&lt;br /&gt;
Mode                    sv&lt;br /&gt;
SubDomains              yes&lt;br /&gt;
# Log to syslog&lt;br /&gt;
Syslog                  yes&lt;br /&gt;
LogWhy                  yes&lt;br /&gt;
# Required to use local socket with MTAs that access the socket as a non-&lt;br /&gt;
# privileged user (e.g. Postfix)&lt;br /&gt;
UMask                   022&lt;br /&gt;
UserID                  opendkim:opendkim&lt;br /&gt;
#&lt;br /&gt;
KeyTable                /etc/opendkim/KeyTable&lt;br /&gt;
SigningTable            /etc/opendkim/SigningTable&lt;br /&gt;
ExternalIgnoreList      /etc/opendkim/TrustedHosts&lt;br /&gt;
InternalHosts           /etc/opendkim/TrustedHosts&lt;br /&gt;
#&lt;br /&gt;
Socket                  inet:8891@localhost&lt;br /&gt;
#EOF&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Voor uitleg over de diverse parameters, kijk bijvoorbeeld op [https://www.digitalocean.com/community/tutorials/how-to-install-and-configure-dkim-with-postfix-on-debian-wheezy deze site].&lt;br /&gt;
&lt;br /&gt;
===Directory structuur===&lt;br /&gt;
Er moet een directory structuur gemaakt worden om trusted hosts, key tables, signing tables en crypto keys op te slaan. Maak daartoe /etc/opendkim aan met daarin de volgende files en directory: &lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@mail-lb1:/etc/opendkim# ls -l&lt;br /&gt;
total 16&lt;br /&gt;
-rw-r--r-- 1 root root   90 May 25 14:23 KeyTable&lt;br /&gt;
-rw-r--r-- 1 root root   38 May 25 14:24 SigningTable&lt;br /&gt;
-rw-r--r-- 1 root root  151 May 28 22:42 TrustedHosts&lt;br /&gt;
drwxr-xr-x 3 root root 4096 May 25 14:26 keys&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
In de directory komen de keys van de domeinen te staan. &lt;br /&gt;
===Key maken===&lt;br /&gt;
Er is een script die maakt de keys aan en voegt de key toe aan de juiste tabellen&lt;br /&gt;
   /usr/local/hobbynet/bin/maakopendkim.sh &#039;&#039;&#039;domeinnaam&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===De Postfix kant===&lt;br /&gt;
Tevens moet in /etc/default/opendkim alles uitgecommentarieerd worden en deze regel toegevoegd worden:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
SOCKET=&amp;quot;inet:8891@localhost&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Dit socket dient aan Postfix bekend te worden gemaakt. Voeg de volgende regels aan /etc/postfix/main.cf toe:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# DKIM&lt;br /&gt;
milter_default_action = accept&lt;br /&gt;
milter_protocol = 2&lt;br /&gt;
smtpd_milters = inet:localhost:8891&lt;br /&gt;
non_smtpd_milters = inet:localhost:8891&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Hierdoor controleert en zet Postfix nu ook dkim handtekeningen. Vergeet niet Postfix te herstarten.&lt;br /&gt;
&lt;br /&gt;
===Testen===&lt;br /&gt;
De configuratie kan worden getest door een lege mail te sturen naar &#039;&#039;&#039;check-auth@verifier.port25.com&#039;&#039;&#039;. Als alles werkt zal in de reply &#039;&#039;&#039;DKIM check: pass&#039;&#039;&#039; staan onder &#039;&#039;&#039;Summary of Results&#039;&#039;&#039;. Voor de geïnteresseerde is het hele bericht opgenomen. &lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
==========================================================&lt;br /&gt;
Summary of Results&lt;br /&gt;
==========================================================&lt;br /&gt;
SPF check:          pass&lt;br /&gt;
&amp;quot;iprev&amp;quot; check:      pass&lt;br /&gt;
DKIM check:         pass&lt;br /&gt;
SpamAssassin check: ham&lt;br /&gt;
&lt;br /&gt;
==========================================================&lt;br /&gt;
Details:&lt;br /&gt;
==========================================================&lt;br /&gt;
&lt;br /&gt;
HELO hostname:  mail-lb1.hobby.nl&lt;br /&gt;
Source IP:      212.72.224.72&lt;br /&gt;
mail-from:      rootmail@hobby.nl&lt;br /&gt;
&lt;br /&gt;
----------------------------------------------------------&lt;br /&gt;
SPF check details:&lt;br /&gt;
----------------------------------------------------------&lt;br /&gt;
Result:         pass&lt;br /&gt;
ID(s) verified: smtp.mailfrom=rootmail@hobby.nl&lt;br /&gt;
&lt;br /&gt;
DNS record(s):&lt;br /&gt;
    hobby.nl. 60 IN TXT &amp;quot;v=spf1 ip4:212.72.224.0/21 ip4:95.97.35.96/29 ip4:80.253.112.0/24 ip4:94.232.160.0/24 ip6:2a02:968::/32 -all&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----------------------------------------------------------&lt;br /&gt;
&amp;quot;iprev&amp;quot; check details:&lt;br /&gt;
----------------------------------------------------------&lt;br /&gt;
Result:         pass (matches mail-lb1.hobby.nl)&lt;br /&gt;
ID(s) verified: policy.iprev=212.72.224.72&lt;br /&gt;
&lt;br /&gt;
DNS record(s):&lt;br /&gt;
    72.224.72.212.in-addr.arpa. 60 IN PTR mail-lb1.hobby.nl.&lt;br /&gt;
    mail-lb1.hobby.nl. 60 IN A 212.72.224.72&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----------------------------------------------------------&lt;br /&gt;
DKIM check details:&lt;br /&gt;
----------------------------------------------------------&lt;br /&gt;
Result:         pass (matches From: rootmail@hobby.nl)&lt;br /&gt;
ID(s) verified: header.d=hobby.nl&lt;br /&gt;
&lt;br /&gt;
Canonicalized Headers:&lt;br /&gt;
    reply-to:rootmail@hobby.nl&#039;0D&#039;&#039;0A&#039;&lt;br /&gt;
    to:check-auth@verifier.port25.com&#039;0D&#039;&#039;0A&#039;&lt;br /&gt;
    from:Hobbynet&#039;20&#039;rootmaill&#039;20&#039;&amp;lt;rootmail@hobby.nl&amp;gt;&#039;0D&#039;&#039;0A&#039;&lt;br /&gt;
    subject:test&#039;0D&#039;&#039;0A&#039;&lt;br /&gt;
    date:Thu,&#039;20&#039;31&#039;20&#039;May&#039;20&#039;2018&#039;20&#039;21:48:24&#039;20&#039;+0200&#039;0D&#039;&#039;0A&#039;&lt;br /&gt;
    dkim-signature:v=1;&#039;20&#039;a=rsa-sha256;&#039;20&#039;c=relaxed/simple;&#039;20&#039;d=hobby.nl;&#039;20&#039;s=default;&#039;20&#039;t=1527796105;&#039;20&#039;bh=frcCV1k9oG9oKj3dpUqdJg1PxRT2RSN/XKdLCPjaYaY=;&#039;20&#039;h=Reply-To:To:From:Subject:Date;&#039;20&#039;b=&lt;br /&gt;
&lt;br /&gt;
Canonicalized Body:&lt;br /&gt;
    &#039;0D&#039;&#039;0A&#039;&lt;br /&gt;
    &lt;br /&gt;
&lt;br /&gt;
DNS record(s):&lt;br /&gt;
    default._domainkey.hobby.nl. 60 IN TXT &amp;quot;v=DKIM1; k=rsa; s=email; p=MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAyHQygiGyUV+o4WTsNIbxfYPyADNedPojfVfn2YrCZJ6WFhBi6RNKKJndqE+VGgtScSI1fkLRCyquVPTGICUAnUbUQL2NbGQNyo0T8wBJy5QTarir10IMue/2QtjaPnDkwa4m35Bl9YKm4SgeaTd7A/OWXsO2BAgCYfiAHsFvK6e6u4zwcD1ZlGH9bSrgm5x6ucHkROq9aV0R0Pr/+SGkT+9Zs1L/TqbX0OvoKmG+raffHVghG8USo1EVWzFSi7gURqP6C8f9HW4HfLnR203C8uJMHSzBvPv5PbM+kc/QTu1AE478a6aZyaUsEhHQQx7OV08crT6UsdyUHQlQpgl8aR+MwAyrEH54AAPzYjfN5KNsZ35flf2/Yj6X5KtGeG0ZVMR2cew1z3SKTFXg+rq+TWF3EqhiD3fzTypSYk5nhKpKpMYtoU7JytF4Xw02fyJpbiVdAGsLqibM+rY+4qp+C/t1HKHVavGePdg5iBE/Y+lOqG6dJvXpWe7JjEz7HfZOz69XN0ryL5/JUzfCpf7lvyJ3LKET4OuBbSwypzNeDX+DaAHb4qdwNFJGq8H0DjFFFagmPQSeHZdX7qTtIiOSbogFXab2Yz9Yw38GedKk9UQPSdCLqdzeFEZWuTXDn/NdRA7PqWuAUxoe68O57Esz4dnyLqB1Xrs74IzTRpLhiSECAwEAAQ==&amp;quot;&lt;br /&gt;
&lt;br /&gt;
Public key used for verification: default._domainkey.hobby.nl (4096 bits)&lt;br /&gt;
&lt;br /&gt;
NOTE: DKIM checking has been performed based on the latest DKIM specs&lt;br /&gt;
(RFC 4871 or draft-ietf-dkim-base-10) and verification may fail for&lt;br /&gt;
older versions.  If you are using Port25&#039;s PowerMTA, you need to use&lt;br /&gt;
version 3.2r11 or later to get a compatible version of DKIM.&lt;br /&gt;
&lt;br /&gt;
----------------------------------------------------------&lt;br /&gt;
SpamAssassin check details:&lt;br /&gt;
----------------------------------------------------------&lt;br /&gt;
SpamAssassin v3.4.0 (2014-02-07)&lt;br /&gt;
&lt;br /&gt;
Result:         ham (-2.0 points, 5.0 required)&lt;br /&gt;
&lt;br /&gt;
 pts rule name              description&lt;br /&gt;
---- ---------------------- --------------------------------------------------&lt;br /&gt;
-0.0 RCVD_IN_DNSWL_NONE     RBL: Sender listed at http://www.dnswl.org/, no&lt;br /&gt;
                            trust&lt;br /&gt;
                            [212.72.224.72 listed in list.dnswl.org]&lt;br /&gt;
-0.0 SPF_PASS               SPF: sender matches SPF record&lt;br /&gt;
-1.9 BAYES_00               BODY: Bayes spam probability is 0 to 1%&lt;br /&gt;
                            [score: 0.0000]&lt;br /&gt;
-0.1 DKIM_VALID_AU          Message has a valid DKIM or DK signature from author&#039;s&lt;br /&gt;
                            domain&lt;br /&gt;
 0.1 DKIM_SIGNED            Message has a DKIM or DK signature, not necessarily valid&lt;br /&gt;
-0.1 DKIM_VALID             Message has at least one valid DKIM or DK signature&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==============================================================&lt;br /&gt;
Explanation of the possible results (based on RFCs 7601, 7208)&lt;br /&gt;
==============================================================&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
DKIM Results&lt;br /&gt;
============&lt;br /&gt;
&lt;br /&gt;
none:  The message was not signed.&lt;br /&gt;
&lt;br /&gt;
pass:  The message was signed, the signature or signatures were&lt;br /&gt;
    acceptable to the ADMD, and the signature(s) passed verification&lt;br /&gt;
    tests.&lt;br /&gt;
&lt;br /&gt;
fail:  The message was signed and the signature or signatures were&lt;br /&gt;
    acceptable to the ADMD, but they failed the verification test(s).&lt;br /&gt;
&lt;br /&gt;
policy:  The message was signed, but some aspect of the signature or&lt;br /&gt;
    signatures was not acceptable to the ADMD.&lt;br /&gt;
&lt;br /&gt;
neutral:  The message was signed, but the signature or signatures&lt;br /&gt;
    contained syntax errors or were not otherwise able to be&lt;br /&gt;
    processed.  This result is also used for other failures not&lt;br /&gt;
    covered elsewhere in this list.&lt;br /&gt;
&lt;br /&gt;
temperror:  The message could not be verified due to some error that&lt;br /&gt;
    is likely transient in nature, such as a temporary inability to&lt;br /&gt;
    retrieve a public key.  A later attempt may produce a final&lt;br /&gt;
    result.&lt;br /&gt;
&lt;br /&gt;
permerror:  The message could not be verified due to some error that&lt;br /&gt;
    is unrecoverable, such as a required header field being absent.  A&lt;br /&gt;
    later attempt is unlikely to produce a final result.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
SPF Results&lt;br /&gt;
===========&lt;br /&gt;
&lt;br /&gt;
none:  Either (a) no syntactically valid DNS domain name was extracted from&lt;br /&gt;
    the SMTP session that could be used as the one to be authorized, or&lt;br /&gt;
    (b) no SPF records were retrieved from the DNS.&lt;br /&gt;
&lt;br /&gt;
neutral:  The ADMD has explicitly stated that it is not asserting whether&lt;br /&gt;
    the IP address is authorized.&lt;br /&gt;
&lt;br /&gt;
pass:  An explicit statement that the client is authorized to inject mail&lt;br /&gt;
    with the given identity.&lt;br /&gt;
&lt;br /&gt;
fail:  An explicit statement that the client is not authorized to use the&lt;br /&gt;
    domain in the given identity.&lt;br /&gt;
&lt;br /&gt;
softfail:  A weak statement by the publishing ADMD that the host is probably&lt;br /&gt;
    not authorized.  It has not published a stronger, more definitive policy&lt;br /&gt;
    that results in a &amp;quot;fail&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
temperror:  The SPF verifier encountered a transient (generally DNS) error&lt;br /&gt;
    while performing the check.  A later retry may succeed without further&lt;br /&gt;
    DNS operator action.&lt;br /&gt;
&lt;br /&gt;
permerror: The domain&#039;s published records could not be correctly interpreted.&lt;br /&gt;
    This signals an error condition that definitely requires DNS operator&lt;br /&gt;
    intervention to be resolved.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;quot;iprev&amp;quot; Results&lt;br /&gt;
===============&lt;br /&gt;
&lt;br /&gt;
pass:  The DNS evaluation succeeded, i.e., the &amp;quot;reverse&amp;quot; and&lt;br /&gt;
    &amp;quot;forward&amp;quot; lookup results were returned and were in agreement.&lt;br /&gt;
&lt;br /&gt;
fail:  The DNS evaluation failed.  In particular, the &amp;quot;reverse&amp;quot; and&lt;br /&gt;
    &amp;quot;forward&amp;quot; lookups each produced results, but they were not in&lt;br /&gt;
    agreement, or the &amp;quot;forward&amp;quot; query completed but produced no&lt;br /&gt;
    result, e.g., a DNS RCODE of 3, commonly known as NXDOMAIN, or an&lt;br /&gt;
    RCODE of 0 (NOERROR) in a reply containing no answers, was&lt;br /&gt;
    returned.&lt;br /&gt;
&lt;br /&gt;
temperror:  The DNS evaluation could not be completed due to some&lt;br /&gt;
    error that is likely transient in nature, such as a temporary DNS&lt;br /&gt;
    error, e.g., a DNS RCODE of 2, commonly known as SERVFAIL, or&lt;br /&gt;
    other error condition resulted.  A later attempt may produce a&lt;br /&gt;
    final result.&lt;br /&gt;
&lt;br /&gt;
permerror:  The DNS evaluation could not be completed because no PTR&lt;br /&gt;
    data are published for the connecting IP address, e.g., a DNS&lt;br /&gt;
    RCODE of 3, commonly known as NXDOMAIN, or an RCODE of 0 (NOERROR)&lt;br /&gt;
    in a reply containing no answers, was returned.  This prevented&lt;br /&gt;
    completion of the evaluation.  A later attempt is unlikely to&lt;br /&gt;
    produce a final result.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==========================================================&lt;br /&gt;
Original Email&lt;br /&gt;
==========================================================&lt;br /&gt;
&lt;br /&gt;
Return-Path: &amp;lt;rootmail@hobby.nl&amp;gt;&lt;br /&gt;
Received: from mail-lb1.hobby.nl (212.72.224.72) by verifier.port25.com id h218om2e8s48 for &amp;lt;check-auth@verifier.port25.com&amp;gt;; Thu, 31 May 2018 19:48:27 +0000 (envelope-from &amp;lt;rootmail@hobby.nl&amp;gt;)&lt;br /&gt;
Authentication-Results: verifier.port25.com; spf=pass  smtp.mailfrom=rootmail@hobby.nl;&lt;br /&gt;
 iprev=pass (matches mail-lb1.hobby.nl)  policy.iprev=212.72.224.72;&lt;br /&gt;
 dkim=pass (matches From: rootmail@hobby.nl)  header.d=hobby.nl&lt;br /&gt;
Received: from localhost (localhost [127.0.0.1])&lt;br /&gt;
	by mail-lb1.hobby.nl (Postfix) with ESMTP id 8396E5FDEA&lt;br /&gt;
	for &amp;lt;check-auth@verifier.port25.com&amp;gt;; Thu, 31 May 2018 21:48:25 +0200 (CEST)&lt;br /&gt;
X-Virus-Scanned: Debian amavisd-new at mail-lb1.hobby.nl&lt;br /&gt;
Received: from mail-lb1.hobby.nl ([127.0.0.1])&lt;br /&gt;
	by localhost (mail-lb1.hobby.nl [127.0.0.1]) (amavisd-new, port 10024)&lt;br /&gt;
	with ESMTP id bnAxJuumS9FK for &amp;lt;check-auth@verifier.port25.com&amp;gt;;&lt;br /&gt;
	Thu, 31 May 2018 21:48:25 +0200 (CEST)&lt;br /&gt;
Received: from [192.168.10.12] (vandenbussche.xs4all.nl [83.163.218.172])&lt;br /&gt;
	(using TLSv1 with cipher ECDHE-RSA-AES128-SHA (128/128 bits))&lt;br /&gt;
	(No client certificate requested)&lt;br /&gt;
	(Authenticated sender: egbert@vandenbussche.nl)&lt;br /&gt;
	by mail-lb1.hobby.nl (Postfix) with ESMTPSA id 51FE55FDE6&lt;br /&gt;
	for &amp;lt;check-auth@verifier.port25.com&amp;gt;; Thu, 31 May 2018 21:48:25 +0200 (CEST)&lt;br /&gt;
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=hobby.nl; s=default;&lt;br /&gt;
	t=1527796105; bh=frcCV1k9oG9oKj3dpUqdJg1PxRT2RSN/XKdLCPjaYaY=;&lt;br /&gt;
	h=Reply-To:To:From:Subject:Date;&lt;br /&gt;
	b=allKIIWMLMVr0ufrCeIkA8T7VF6xZ9PpPDEG80vqoQraDkwa8FAal+ZXhK/Y/nwtO&lt;br /&gt;
	 XYzhEZmOHSYtvTplFppuvXCsbK2q/ZYf881CounLX/w+Ko0ZNIgJwsOz7WX7MJLDXS&lt;br /&gt;
	 cp13/hRVzNYv0LBsI1sz6cXKkNhVxWEShaIjsSW84bQgAAznR0zG9ZYLuVEXm614T0&lt;br /&gt;
	 cz56At+ONbF/8wqBy3rYRBjJ+66xvajO5DfKX94zJErCpvyoiTYCtO5uf0H3sIsiDs&lt;br /&gt;
	 l7a7IUV3Ituzw0+VNpnRP1J3cNxI7j51EGaoUI1w501cCV6f0wC/qbXd9UVHBAl78g&lt;br /&gt;
	 84j+gS4ImtTe9hR3llRnW+2TfuWradddBjUSkX1UiZDORvMkZM+J2pCgFYxU1GXoR+&lt;br /&gt;
	 GHnDPYqW9KDfuVAHUYU6iZ4eDrijS/Y5OBhix1mAX4/XkYaagpbXD9tr/43nNGV3YU&lt;br /&gt;
	 O8S91tFCgik86DfD5b98lxrr61KHb0X/brYF9l8oBvG9L9nuK0g9r90NeLwhmn88dm&lt;br /&gt;
	 Ll4wN0yIHI3yxEQtli6CdZ4H6gJczv6CRp74U/oNyO8PWIm7Nu4grCtWNPXuOzcHjr&lt;br /&gt;
	 FsGPJun8WFVjwVPeKoEOgUTI27g4nfbHkXQEBb9ykQVvVpe44RXbruS81rfKoPThAw&lt;br /&gt;
	 AU/un1L18tPKxUU+jtT2m2hI=&lt;br /&gt;
Reply-To: rootmail@hobby.nl&lt;br /&gt;
To: check-auth@verifier.port25.com&lt;br /&gt;
From: Hobbynet rootmaill &amp;lt;rootmail@hobby.nl&amp;gt;&lt;br /&gt;
Subject: test&lt;br /&gt;
Openpgp: preference=signencrypt&lt;br /&gt;
Autocrypt: addr=rootmail@hobby.nl; prefer-encrypt=mutual; keydata=&lt;br /&gt;
 xsFNBFZ2htYBEADt6zlAySAIrmfb6mRkAPuekeaAM6jIw6n4vdcpGdYi1fL63uZypoh61Ra7&lt;br /&gt;
 lF8SGs3uNhR6EyfJt/54Wsfami+KE4x5nd0dwPAWEwMaruxwKHBmGU1X/895EoRa3aa6PsEc&lt;br /&gt;
 SGyfJplaCscyTneEdsrhtdqKdJi/be8YunhAuYfu1rEaT8FU+hz1itWJJ/YZycscSA8Cb91d&lt;br /&gt;
 w8dUkJamdK0KtaHXOq0pZcJPICtzd0zQIYuouJM1nAjPqQ6GYWu+TebJorWlrHKIzX9WCE1D&lt;br /&gt;
 4wxktMXC+CCwRrV7YLV48ouMuqFejEYvBPjdiIqfxI+vw3bYmtRg0aQ0i3cvadnq6rYS1P6Y&lt;br /&gt;
 nAKk3U1v1Pr83FPUCgTFTpQqHbNJiRDa3tFkVFrY7YtnW4+iHJ8gT2HLOkzpxq/jkhf6gwSQ&lt;br /&gt;
 GgzAf7hepWBUWpKsd501ezVSoza3WQ4laIqvUaYcMGpdeY2vkHASuBulF/QyOk25PBQGVMjL&lt;br /&gt;
 IKovZKIkCp3ghXmYeNjMvtIih3Zh3edH4eekVpP4tgFkdddwguA/yEYYyvFv8KGBvBrQCMzF&lt;br /&gt;
 ghhDRJ6cZL1ewEwuVkGH9qXlM/Gfw4NUo/APuGbbU2PXSxzdxOxbJX2XuRripIsVTVwWKAeb&lt;br /&gt;
 SAitSSFP8B5talGvV3pKooYxAMNa27LRkoZbMjSOVFJ2yeIUHQARAQABzSBFZ2JlcnQgPGVn&lt;br /&gt;
 YmVydEB2YW5kZW5idXNzY2hlLm5sPsLBggQTAQgALAIbIwUJCWYBgAcLCQgHAwIBBhUIAgkK&lt;br /&gt;
 CwQWAgMBAh4BAheABQJWdoj5AhkBAAoJEElE8PvYS2x3wFYP/jy1Ym+6oQDPuHNauYnujpe5&lt;br /&gt;
 DyZOUrPTHdDqg+HjSXzoozeQGeKpIeAZj7ZXSpfGr4mPaPn8gaWxr6ibQAkVYvTZ4MttoqFo&lt;br /&gt;
 cT3ePbUGHnagNcwAZJlcoNJQ6S92YYVWryFn0F8JMUcnQzUaJyUOIaf5pcdJcbA6bPBcMa8X&lt;br /&gt;
 oHSEyD48Dauir7QpsDTurfTooRBZrlLXMkQCeO+FR2R+2WXt7JxQEv1tDZ6xCS/CTMdibszn&lt;br /&gt;
 fQqlEMj6qNdLh7ymM8umqFlfPx8xRTom8ClkhJryDpV3yYiz380aOt3SCzee68GOwXyM98+P&lt;br /&gt;
 GD9QSzlhxjh6GF5bhW4jEH5uLByjIUQNDIBDvuqSIWWnBE39zoGqvlAlO9ZOtYaHprCREBkF&lt;br /&gt;
 IQHiHqOLMkzBHkHJOrqmROkDXpUSeso1rQZEo/13axZyu4JCgHEGONhCDrzZWjK2ASPQZzjL&lt;br /&gt;
 dAKkuvfIJlwS0yctYWcaK6ttPLyteujWjHbfvJRT6BRLlr0YnmSZs86xWpYnXMrG9xa886Us&lt;br /&gt;
 kswQd7c2QZuBpLgHW3KzrFvCd/LKp3UvPiVUigK6Xgoi7xwwxfv8O4EeZYO2U35w5SPlg+Mz&lt;br /&gt;
 FEJVH2whxboMrHZRhLtyPKY0+qqkLP2LxphUAeNRWNOJIXiazTq1/4Y5dVK1zIq6gg2dBMmH&lt;br /&gt;
 PHx8fQAnhphZzsFNBFZ2htYBEAC7NDbfwBKMD8VRlVUxIds4+0SGsRUhwHQJrU0Tn8vzFiRS&lt;br /&gt;
 GBtDuOdAPyt8GDrjh2c2PKno9piQnbojqKGJ0HvGoHzfm9axb0S4CPgGfcIrSjyQIu4+kpCj&lt;br /&gt;
 tatSaxtuvqqpxNBx9ylfubJgTKW96m8K8twbXc6QczMsd6zSt4U5ER8EWrlT1JB+mW+hNuQW&lt;br /&gt;
 4VQ1A6f0JRQqXOA1b23yNW621CfT9r9t4OpDug9vWyGXyQjjLoiMRsGVH5B/37UXn2BS14wh&lt;br /&gt;
 2xLj+eh9V1pN4S1IZVv/k0EdRwn9VC/bSGgTbk6P6oOM7LrV+BM7yQHoFOO5HPb2jJB+ynVu&lt;br /&gt;
 K4/n0Xe/Zcfp2OPAm9qn5Z0lkTSHRxvCMWxxNoAgirzj/KdNnuDVU7SdRulynIcczqj68adV&lt;br /&gt;
 uEyPeu1mwhOTku7eQnlFmGhkD5oJfg/IPdb7OmnpWsFPfyowG/nR7oPAFVkoNfRRqtUpHIM4&lt;br /&gt;
 k+2Xm/lWxYHzlzVF9SzbLWKs3/J9tyVb7xNAlr8gcbwgO8bOwWUiAG6hSMD1yLdox92seRPY&lt;br /&gt;
 mnhOC6PCG3KKqCH7wBZ84Ez0BDqYDqSzq4/PlCnJrMk3ewb/fuGiMF7kgYHThvdZUeyRgUoY&lt;br /&gt;
 yG7i3R3XRFDUiN5m7SyuRUUdgHwznb2e8Pf/IMYtTZh737bgM+mWc/YlJq+cmQARAQABwsFl&lt;br /&gt;
 BBgBCAAPBQJWdobWAhsMBQkJZgGAAAoJEElE8PvYS2x3Ad0QAN/WS9Mc0MdhJi7fqhq5dU4X&lt;br /&gt;
 QfviUMA5CkWboNiOG57OR1C0a4XJcFCDcgmsYRhMYDj4qw7M+z3fcjFJnEwqHHoIhzsvGbDs&lt;br /&gt;
 Dra8QkP188tx+Uzf4wMnEVCVzOuL5ji36OlxegF5wjj5CTtso237hhcI82+xAnqXteA5pJMw&lt;br /&gt;
 DunRmhEkjpJjxkUtr4vyOSzGBmMP3sWGbq0uVbWacxggb1r56+uKrQULVEnCa4P64d8RPKn7&lt;br /&gt;
 Dsn/Pqf7n+nLevBertj5roQNceXeGIpu0k45wVFUtCA9Rc1Y6myNs0aq8Cw5LKTLemI+uT4y&lt;br /&gt;
 Okky89vroZqG/XetHAXxjZGm+kyMbu3ThvIzOSb5+hTfWcTa8zybUvujkfiejfhRDZ9GWjXS&lt;br /&gt;
 iK20nZ8d2WwTqPDOMySozXFUJoT6TqTJ/I7m9vJj2mz+xPRLHaAVVKF7rMP8Gw+6g9uWbHs1&lt;br /&gt;
 SXAZH/CgQTAJwQ+FxWC657Q+bjg11lmjCHpDMxxFnIdqYiIaKjocQzI2SP67Yr94W0trumOR&lt;br /&gt;
 fZm3nietLoSVVkak0z+SBJZ4/S+XbkDmLnUDG3GJq/QCXFAFVv02VS76gvVYaxFuVWOUIuXf&lt;br /&gt;
 SkWKoa6vs12Cx30Hp/BfdftCHH6IuhzXspKK+br9CqDrRZcHzMB42/QPYcDa/BZBzudBXsZd&lt;br /&gt;
 M+CrfDxPMyd7&lt;br /&gt;
Organization: HCC!Hobbynet&lt;br /&gt;
Message-ID: &amp;lt;bc4cc04a-de4c-54f7-37c4-ffb6f589fb4b@hobby.nl&amp;gt;&lt;br /&gt;
Date: Thu, 31 May 2018 21:48:24 +0200&lt;br /&gt;
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101&lt;br /&gt;
 Thunderbird/52.8.0&lt;br /&gt;
MIME-Version: 1.0&lt;br /&gt;
Content-Type: text/plain; charset=utf-8&lt;br /&gt;
Content-Language: nl&lt;br /&gt;
Content-Transfer-Encoding: 7bit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>2A05:F080:0:300:B848:81C0:7F18:AA86</name></author>
	</entry>
	<entry>
		<id>https://wiki.hobby.nl/index.php?title=DKIM&amp;diff=78338</id>
		<title>DKIM</title>
		<link rel="alternate" type="text/html" href="https://wiki.hobby.nl/index.php?title=DKIM&amp;diff=78338"/>
		<updated>2020-04-05T11:02:51Z</updated>

		<summary type="html">&lt;p&gt;2A05:F080:0:300:B848:81C0:7F18:AA86: /* Directory structuur */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;===Inleiding===&lt;br /&gt;
Om minder snel als spammer te worden aangemerkt kan de mail &amp;quot;ge-signed&amp;quot; worden. Hiervoor moet OpenDKIM geinstalleerd worden en een kleine aanpassing aan de postfix configuratie gemaakt worden.&lt;br /&gt;
===Installatie===&lt;br /&gt;
Gebruik zoals altijd apt-get of aptitude om een package te instaleren.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
apt-get install opendkim opendkim-tools&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
===Configuratie===&lt;br /&gt;
De configuratie van OpenDKIM staat in /etc/opendkim.conf en dient er als volgt ui te zien:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# This is a basic configuration that can easily be adapted to suit a standard&lt;br /&gt;
# installation. For more advanced options, see opendkim.conf(5) and/or&lt;br /&gt;
# /usr/share/doc/opendkim/examples/opendkim.conf.sample.&lt;br /&gt;
#&lt;br /&gt;
#Domain                  example.com&lt;br /&gt;
#KeyFile                 /etc/opendkim/201205.private&lt;br /&gt;
#Selector                201205&lt;br /&gt;
#&lt;br /&gt;
# Commonly-used options&lt;br /&gt;
Canonicalization        relaxed/simple&lt;br /&gt;
Mode                    sv&lt;br /&gt;
SubDomains              yes&lt;br /&gt;
# Log to syslog&lt;br /&gt;
Syslog                  yes&lt;br /&gt;
LogWhy                  yes&lt;br /&gt;
# Required to use local socket with MTAs that access the socket as a non-&lt;br /&gt;
# privileged user (e.g. Postfix)&lt;br /&gt;
UMask                   022&lt;br /&gt;
UserID                  opendkim:opendkim&lt;br /&gt;
#&lt;br /&gt;
KeyTable                /etc/opendkim/KeyTable&lt;br /&gt;
SigningTable            /etc/opendkim/SigningTable&lt;br /&gt;
ExternalIgnoreList      /etc/opendkim/TrustedHosts&lt;br /&gt;
InternalHosts           /etc/opendkim/TrustedHosts&lt;br /&gt;
#&lt;br /&gt;
Socket                  inet:8891@localhost&lt;br /&gt;
#EOF&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Voor uitleg over de diverse parameters, kijk bijvoorbeeld op [https://www.digitalocean.com/community/tutorials/how-to-install-and-configure-dkim-with-postfix-on-debian-wheezy deze site].&lt;br /&gt;
&lt;br /&gt;
===Directory structuur===&lt;br /&gt;
Er moet een directory structuur gemaakt worden om trusted hosts, key tables, signing tables en crypto keys op te slaan. Maak daartoe /etc/opendkim aan met daarin de volgende files en directory: &lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@mail-lb1:/etc/opendkim# ls -l&lt;br /&gt;
total 16&lt;br /&gt;
-rw-r--r-- 1 root root   90 May 25 14:23 KeyTable&lt;br /&gt;
-rw-r--r-- 1 root root   38 May 25 14:24 SigningTable&lt;br /&gt;
-rw-r--r-- 1 root root  151 May 28 22:42 TrustedHosts&lt;br /&gt;
drwxr-xr-x 3 root root 4096 May 25 14:26 keys&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
In de directory komen de keys van de domeinen te staan. &lt;br /&gt;
===Key maken===&lt;br /&gt;
Er is een script die maakt de keys aan en voegt de key toe aan de juiste tabellen&lt;br /&gt;
   /usr/local/hobbynet/bin/maakopendkim.sh &#039;&#039;&#039;domeinnaam&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
===De Postfix kant===&lt;br /&gt;
Tevens moet in /etc/default/opendkim alles uitgecommentarieerd worden en deze regel toegevoegd worden:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
SOCKET=&amp;quot;inet:8891@localhost&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Dit socket dient aan Postfix bekend te worden gemaakt. Voeg de volgende regels aan /etc/postfix/main.cf toe:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#milter tbv dkim&lt;br /&gt;
milter_default_action = accept&lt;br /&gt;
milter_protocol = 6&lt;br /&gt;
smtpd_milters = inet:localhost:8891&lt;br /&gt;
non_smtpd_milters = inet:localhost:8891&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Hierdoor controleert en zet Postfix nu ook dkim handtekeningen. Vergeet niet Postfix te herstarten.&lt;br /&gt;
===Testen===&lt;br /&gt;
De configuratie kan worden getest door een lege mail te sturen naar &#039;&#039;&#039;check-auth@verifier.port25.com&#039;&#039;&#039;. Als alles werkt zal in de reply &#039;&#039;&#039;DKIM check: pass&#039;&#039;&#039; staan onder &#039;&#039;&#039;Summary of Results&#039;&#039;&#039;. Voor de geïnteresseerde is het hele bericht opgenomen. &lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
==========================================================&lt;br /&gt;
Summary of Results&lt;br /&gt;
==========================================================&lt;br /&gt;
SPF check:          pass&lt;br /&gt;
&amp;quot;iprev&amp;quot; check:      pass&lt;br /&gt;
DKIM check:         pass&lt;br /&gt;
SpamAssassin check: ham&lt;br /&gt;
&lt;br /&gt;
==========================================================&lt;br /&gt;
Details:&lt;br /&gt;
==========================================================&lt;br /&gt;
&lt;br /&gt;
HELO hostname:  mail-lb1.hobby.nl&lt;br /&gt;
Source IP:      212.72.224.72&lt;br /&gt;
mail-from:      rootmail@hobby.nl&lt;br /&gt;
&lt;br /&gt;
----------------------------------------------------------&lt;br /&gt;
SPF check details:&lt;br /&gt;
----------------------------------------------------------&lt;br /&gt;
Result:         pass&lt;br /&gt;
ID(s) verified: smtp.mailfrom=rootmail@hobby.nl&lt;br /&gt;
&lt;br /&gt;
DNS record(s):&lt;br /&gt;
    hobby.nl. 60 IN TXT &amp;quot;v=spf1 ip4:212.72.224.0/21 ip4:95.97.35.96/29 ip4:80.253.112.0/24 ip4:94.232.160.0/24 ip6:2a02:968::/32 -all&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----------------------------------------------------------&lt;br /&gt;
&amp;quot;iprev&amp;quot; check details:&lt;br /&gt;
----------------------------------------------------------&lt;br /&gt;
Result:         pass (matches mail-lb1.hobby.nl)&lt;br /&gt;
ID(s) verified: policy.iprev=212.72.224.72&lt;br /&gt;
&lt;br /&gt;
DNS record(s):&lt;br /&gt;
    72.224.72.212.in-addr.arpa. 60 IN PTR mail-lb1.hobby.nl.&lt;br /&gt;
    mail-lb1.hobby.nl. 60 IN A 212.72.224.72&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----------------------------------------------------------&lt;br /&gt;
DKIM check details:&lt;br /&gt;
----------------------------------------------------------&lt;br /&gt;
Result:         pass (matches From: rootmail@hobby.nl)&lt;br /&gt;
ID(s) verified: header.d=hobby.nl&lt;br /&gt;
&lt;br /&gt;
Canonicalized Headers:&lt;br /&gt;
    reply-to:rootmail@hobby.nl&#039;0D&#039;&#039;0A&#039;&lt;br /&gt;
    to:check-auth@verifier.port25.com&#039;0D&#039;&#039;0A&#039;&lt;br /&gt;
    from:Hobbynet&#039;20&#039;rootmaill&#039;20&#039;&amp;lt;rootmail@hobby.nl&amp;gt;&#039;0D&#039;&#039;0A&#039;&lt;br /&gt;
    subject:test&#039;0D&#039;&#039;0A&#039;&lt;br /&gt;
    date:Thu,&#039;20&#039;31&#039;20&#039;May&#039;20&#039;2018&#039;20&#039;21:48:24&#039;20&#039;+0200&#039;0D&#039;&#039;0A&#039;&lt;br /&gt;
    dkim-signature:v=1;&#039;20&#039;a=rsa-sha256;&#039;20&#039;c=relaxed/simple;&#039;20&#039;d=hobby.nl;&#039;20&#039;s=default;&#039;20&#039;t=1527796105;&#039;20&#039;bh=frcCV1k9oG9oKj3dpUqdJg1PxRT2RSN/XKdLCPjaYaY=;&#039;20&#039;h=Reply-To:To:From:Subject:Date;&#039;20&#039;b=&lt;br /&gt;
&lt;br /&gt;
Canonicalized Body:&lt;br /&gt;
    &#039;0D&#039;&#039;0A&#039;&lt;br /&gt;
    &lt;br /&gt;
&lt;br /&gt;
DNS record(s):&lt;br /&gt;
    default._domainkey.hobby.nl. 60 IN TXT &amp;quot;v=DKIM1; k=rsa; s=email; p=MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAyHQygiGyUV+o4WTsNIbxfYPyADNedPojfVfn2YrCZJ6WFhBi6RNKKJndqE+VGgtScSI1fkLRCyquVPTGICUAnUbUQL2NbGQNyo0T8wBJy5QTarir10IMue/2QtjaPnDkwa4m35Bl9YKm4SgeaTd7A/OWXsO2BAgCYfiAHsFvK6e6u4zwcD1ZlGH9bSrgm5x6ucHkROq9aV0R0Pr/+SGkT+9Zs1L/TqbX0OvoKmG+raffHVghG8USo1EVWzFSi7gURqP6C8f9HW4HfLnR203C8uJMHSzBvPv5PbM+kc/QTu1AE478a6aZyaUsEhHQQx7OV08crT6UsdyUHQlQpgl8aR+MwAyrEH54AAPzYjfN5KNsZ35flf2/Yj6X5KtGeG0ZVMR2cew1z3SKTFXg+rq+TWF3EqhiD3fzTypSYk5nhKpKpMYtoU7JytF4Xw02fyJpbiVdAGsLqibM+rY+4qp+C/t1HKHVavGePdg5iBE/Y+lOqG6dJvXpWe7JjEz7HfZOz69XN0ryL5/JUzfCpf7lvyJ3LKET4OuBbSwypzNeDX+DaAHb4qdwNFJGq8H0DjFFFagmPQSeHZdX7qTtIiOSbogFXab2Yz9Yw38GedKk9UQPSdCLqdzeFEZWuTXDn/NdRA7PqWuAUxoe68O57Esz4dnyLqB1Xrs74IzTRpLhiSECAwEAAQ==&amp;quot;&lt;br /&gt;
&lt;br /&gt;
Public key used for verification: default._domainkey.hobby.nl (4096 bits)&lt;br /&gt;
&lt;br /&gt;
NOTE: DKIM checking has been performed based on the latest DKIM specs&lt;br /&gt;
(RFC 4871 or draft-ietf-dkim-base-10) and verification may fail for&lt;br /&gt;
older versions.  If you are using Port25&#039;s PowerMTA, you need to use&lt;br /&gt;
version 3.2r11 or later to get a compatible version of DKIM.&lt;br /&gt;
&lt;br /&gt;
----------------------------------------------------------&lt;br /&gt;
SpamAssassin check details:&lt;br /&gt;
----------------------------------------------------------&lt;br /&gt;
SpamAssassin v3.4.0 (2014-02-07)&lt;br /&gt;
&lt;br /&gt;
Result:         ham (-2.0 points, 5.0 required)&lt;br /&gt;
&lt;br /&gt;
 pts rule name              description&lt;br /&gt;
---- ---------------------- --------------------------------------------------&lt;br /&gt;
-0.0 RCVD_IN_DNSWL_NONE     RBL: Sender listed at http://www.dnswl.org/, no&lt;br /&gt;
                            trust&lt;br /&gt;
                            [212.72.224.72 listed in list.dnswl.org]&lt;br /&gt;
-0.0 SPF_PASS               SPF: sender matches SPF record&lt;br /&gt;
-1.9 BAYES_00               BODY: Bayes spam probability is 0 to 1%&lt;br /&gt;
                            [score: 0.0000]&lt;br /&gt;
-0.1 DKIM_VALID_AU          Message has a valid DKIM or DK signature from author&#039;s&lt;br /&gt;
                            domain&lt;br /&gt;
 0.1 DKIM_SIGNED            Message has a DKIM or DK signature, not necessarily valid&lt;br /&gt;
-0.1 DKIM_VALID             Message has at least one valid DKIM or DK signature&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==============================================================&lt;br /&gt;
Explanation of the possible results (based on RFCs 7601, 7208)&lt;br /&gt;
==============================================================&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
DKIM Results&lt;br /&gt;
============&lt;br /&gt;
&lt;br /&gt;
none:  The message was not signed.&lt;br /&gt;
&lt;br /&gt;
pass:  The message was signed, the signature or signatures were&lt;br /&gt;
    acceptable to the ADMD, and the signature(s) passed verification&lt;br /&gt;
    tests.&lt;br /&gt;
&lt;br /&gt;
fail:  The message was signed and the signature or signatures were&lt;br /&gt;
    acceptable to the ADMD, but they failed the verification test(s).&lt;br /&gt;
&lt;br /&gt;
policy:  The message was signed, but some aspect of the signature or&lt;br /&gt;
    signatures was not acceptable to the ADMD.&lt;br /&gt;
&lt;br /&gt;
neutral:  The message was signed, but the signature or signatures&lt;br /&gt;
    contained syntax errors or were not otherwise able to be&lt;br /&gt;
    processed.  This result is also used for other failures not&lt;br /&gt;
    covered elsewhere in this list.&lt;br /&gt;
&lt;br /&gt;
temperror:  The message could not be verified due to some error that&lt;br /&gt;
    is likely transient in nature, such as a temporary inability to&lt;br /&gt;
    retrieve a public key.  A later attempt may produce a final&lt;br /&gt;
    result.&lt;br /&gt;
&lt;br /&gt;
permerror:  The message could not be verified due to some error that&lt;br /&gt;
    is unrecoverable, such as a required header field being absent.  A&lt;br /&gt;
    later attempt is unlikely to produce a final result.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
SPF Results&lt;br /&gt;
===========&lt;br /&gt;
&lt;br /&gt;
none:  Either (a) no syntactically valid DNS domain name was extracted from&lt;br /&gt;
    the SMTP session that could be used as the one to be authorized, or&lt;br /&gt;
    (b) no SPF records were retrieved from the DNS.&lt;br /&gt;
&lt;br /&gt;
neutral:  The ADMD has explicitly stated that it is not asserting whether&lt;br /&gt;
    the IP address is authorized.&lt;br /&gt;
&lt;br /&gt;
pass:  An explicit statement that the client is authorized to inject mail&lt;br /&gt;
    with the given identity.&lt;br /&gt;
&lt;br /&gt;
fail:  An explicit statement that the client is not authorized to use the&lt;br /&gt;
    domain in the given identity.&lt;br /&gt;
&lt;br /&gt;
softfail:  A weak statement by the publishing ADMD that the host is probably&lt;br /&gt;
    not authorized.  It has not published a stronger, more definitive policy&lt;br /&gt;
    that results in a &amp;quot;fail&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
temperror:  The SPF verifier encountered a transient (generally DNS) error&lt;br /&gt;
    while performing the check.  A later retry may succeed without further&lt;br /&gt;
    DNS operator action.&lt;br /&gt;
&lt;br /&gt;
permerror: The domain&#039;s published records could not be correctly interpreted.&lt;br /&gt;
    This signals an error condition that definitely requires DNS operator&lt;br /&gt;
    intervention to be resolved.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;quot;iprev&amp;quot; Results&lt;br /&gt;
===============&lt;br /&gt;
&lt;br /&gt;
pass:  The DNS evaluation succeeded, i.e., the &amp;quot;reverse&amp;quot; and&lt;br /&gt;
    &amp;quot;forward&amp;quot; lookup results were returned and were in agreement.&lt;br /&gt;
&lt;br /&gt;
fail:  The DNS evaluation failed.  In particular, the &amp;quot;reverse&amp;quot; and&lt;br /&gt;
    &amp;quot;forward&amp;quot; lookups each produced results, but they were not in&lt;br /&gt;
    agreement, or the &amp;quot;forward&amp;quot; query completed but produced no&lt;br /&gt;
    result, e.g., a DNS RCODE of 3, commonly known as NXDOMAIN, or an&lt;br /&gt;
    RCODE of 0 (NOERROR) in a reply containing no answers, was&lt;br /&gt;
    returned.&lt;br /&gt;
&lt;br /&gt;
temperror:  The DNS evaluation could not be completed due to some&lt;br /&gt;
    error that is likely transient in nature, such as a temporary DNS&lt;br /&gt;
    error, e.g., a DNS RCODE of 2, commonly known as SERVFAIL, or&lt;br /&gt;
    other error condition resulted.  A later attempt may produce a&lt;br /&gt;
    final result.&lt;br /&gt;
&lt;br /&gt;
permerror:  The DNS evaluation could not be completed because no PTR&lt;br /&gt;
    data are published for the connecting IP address, e.g., a DNS&lt;br /&gt;
    RCODE of 3, commonly known as NXDOMAIN, or an RCODE of 0 (NOERROR)&lt;br /&gt;
    in a reply containing no answers, was returned.  This prevented&lt;br /&gt;
    completion of the evaluation.  A later attempt is unlikely to&lt;br /&gt;
    produce a final result.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==========================================================&lt;br /&gt;
Original Email&lt;br /&gt;
==========================================================&lt;br /&gt;
&lt;br /&gt;
Return-Path: &amp;lt;rootmail@hobby.nl&amp;gt;&lt;br /&gt;
Received: from mail-lb1.hobby.nl (212.72.224.72) by verifier.port25.com id h218om2e8s48 for &amp;lt;check-auth@verifier.port25.com&amp;gt;; Thu, 31 May 2018 19:48:27 +0000 (envelope-from &amp;lt;rootmail@hobby.nl&amp;gt;)&lt;br /&gt;
Authentication-Results: verifier.port25.com; spf=pass  smtp.mailfrom=rootmail@hobby.nl;&lt;br /&gt;
 iprev=pass (matches mail-lb1.hobby.nl)  policy.iprev=212.72.224.72;&lt;br /&gt;
 dkim=pass (matches From: rootmail@hobby.nl)  header.d=hobby.nl&lt;br /&gt;
Received: from localhost (localhost [127.0.0.1])&lt;br /&gt;
	by mail-lb1.hobby.nl (Postfix) with ESMTP id 8396E5FDEA&lt;br /&gt;
	for &amp;lt;check-auth@verifier.port25.com&amp;gt;; Thu, 31 May 2018 21:48:25 +0200 (CEST)&lt;br /&gt;
X-Virus-Scanned: Debian amavisd-new at mail-lb1.hobby.nl&lt;br /&gt;
Received: from mail-lb1.hobby.nl ([127.0.0.1])&lt;br /&gt;
	by localhost (mail-lb1.hobby.nl [127.0.0.1]) (amavisd-new, port 10024)&lt;br /&gt;
	with ESMTP id bnAxJuumS9FK for &amp;lt;check-auth@verifier.port25.com&amp;gt;;&lt;br /&gt;
	Thu, 31 May 2018 21:48:25 +0200 (CEST)&lt;br /&gt;
Received: from [192.168.10.12] (vandenbussche.xs4all.nl [83.163.218.172])&lt;br /&gt;
	(using TLSv1 with cipher ECDHE-RSA-AES128-SHA (128/128 bits))&lt;br /&gt;
	(No client certificate requested)&lt;br /&gt;
	(Authenticated sender: egbert@vandenbussche.nl)&lt;br /&gt;
	by mail-lb1.hobby.nl (Postfix) with ESMTPSA id 51FE55FDE6&lt;br /&gt;
	for &amp;lt;check-auth@verifier.port25.com&amp;gt;; Thu, 31 May 2018 21:48:25 +0200 (CEST)&lt;br /&gt;
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=hobby.nl; s=default;&lt;br /&gt;
	t=1527796105; bh=frcCV1k9oG9oKj3dpUqdJg1PxRT2RSN/XKdLCPjaYaY=;&lt;br /&gt;
	h=Reply-To:To:From:Subject:Date;&lt;br /&gt;
	b=allKIIWMLMVr0ufrCeIkA8T7VF6xZ9PpPDEG80vqoQraDkwa8FAal+ZXhK/Y/nwtO&lt;br /&gt;
	 XYzhEZmOHSYtvTplFppuvXCsbK2q/ZYf881CounLX/w+Ko0ZNIgJwsOz7WX7MJLDXS&lt;br /&gt;
	 cp13/hRVzNYv0LBsI1sz6cXKkNhVxWEShaIjsSW84bQgAAznR0zG9ZYLuVEXm614T0&lt;br /&gt;
	 cz56At+ONbF/8wqBy3rYRBjJ+66xvajO5DfKX94zJErCpvyoiTYCtO5uf0H3sIsiDs&lt;br /&gt;
	 l7a7IUV3Ituzw0+VNpnRP1J3cNxI7j51EGaoUI1w501cCV6f0wC/qbXd9UVHBAl78g&lt;br /&gt;
	 84j+gS4ImtTe9hR3llRnW+2TfuWradddBjUSkX1UiZDORvMkZM+J2pCgFYxU1GXoR+&lt;br /&gt;
	 GHnDPYqW9KDfuVAHUYU6iZ4eDrijS/Y5OBhix1mAX4/XkYaagpbXD9tr/43nNGV3YU&lt;br /&gt;
	 O8S91tFCgik86DfD5b98lxrr61KHb0X/brYF9l8oBvG9L9nuK0g9r90NeLwhmn88dm&lt;br /&gt;
	 Ll4wN0yIHI3yxEQtli6CdZ4H6gJczv6CRp74U/oNyO8PWIm7Nu4grCtWNPXuOzcHjr&lt;br /&gt;
	 FsGPJun8WFVjwVPeKoEOgUTI27g4nfbHkXQEBb9ykQVvVpe44RXbruS81rfKoPThAw&lt;br /&gt;
	 AU/un1L18tPKxUU+jtT2m2hI=&lt;br /&gt;
Reply-To: rootmail@hobby.nl&lt;br /&gt;
To: check-auth@verifier.port25.com&lt;br /&gt;
From: Hobbynet rootmaill &amp;lt;rootmail@hobby.nl&amp;gt;&lt;br /&gt;
Subject: test&lt;br /&gt;
Openpgp: preference=signencrypt&lt;br /&gt;
Autocrypt: addr=rootmail@hobby.nl; prefer-encrypt=mutual; keydata=&lt;br /&gt;
 xsFNBFZ2htYBEADt6zlAySAIrmfb6mRkAPuekeaAM6jIw6n4vdcpGdYi1fL63uZypoh61Ra7&lt;br /&gt;
 lF8SGs3uNhR6EyfJt/54Wsfami+KE4x5nd0dwPAWEwMaruxwKHBmGU1X/895EoRa3aa6PsEc&lt;br /&gt;
 SGyfJplaCscyTneEdsrhtdqKdJi/be8YunhAuYfu1rEaT8FU+hz1itWJJ/YZycscSA8Cb91d&lt;br /&gt;
 w8dUkJamdK0KtaHXOq0pZcJPICtzd0zQIYuouJM1nAjPqQ6GYWu+TebJorWlrHKIzX9WCE1D&lt;br /&gt;
 4wxktMXC+CCwRrV7YLV48ouMuqFejEYvBPjdiIqfxI+vw3bYmtRg0aQ0i3cvadnq6rYS1P6Y&lt;br /&gt;
 nAKk3U1v1Pr83FPUCgTFTpQqHbNJiRDa3tFkVFrY7YtnW4+iHJ8gT2HLOkzpxq/jkhf6gwSQ&lt;br /&gt;
 GgzAf7hepWBUWpKsd501ezVSoza3WQ4laIqvUaYcMGpdeY2vkHASuBulF/QyOk25PBQGVMjL&lt;br /&gt;
 IKovZKIkCp3ghXmYeNjMvtIih3Zh3edH4eekVpP4tgFkdddwguA/yEYYyvFv8KGBvBrQCMzF&lt;br /&gt;
 ghhDRJ6cZL1ewEwuVkGH9qXlM/Gfw4NUo/APuGbbU2PXSxzdxOxbJX2XuRripIsVTVwWKAeb&lt;br /&gt;
 SAitSSFP8B5talGvV3pKooYxAMNa27LRkoZbMjSOVFJ2yeIUHQARAQABzSBFZ2JlcnQgPGVn&lt;br /&gt;
 YmVydEB2YW5kZW5idXNzY2hlLm5sPsLBggQTAQgALAIbIwUJCWYBgAcLCQgHAwIBBhUIAgkK&lt;br /&gt;
 CwQWAgMBAh4BAheABQJWdoj5AhkBAAoJEElE8PvYS2x3wFYP/jy1Ym+6oQDPuHNauYnujpe5&lt;br /&gt;
 DyZOUrPTHdDqg+HjSXzoozeQGeKpIeAZj7ZXSpfGr4mPaPn8gaWxr6ibQAkVYvTZ4MttoqFo&lt;br /&gt;
 cT3ePbUGHnagNcwAZJlcoNJQ6S92YYVWryFn0F8JMUcnQzUaJyUOIaf5pcdJcbA6bPBcMa8X&lt;br /&gt;
 oHSEyD48Dauir7QpsDTurfTooRBZrlLXMkQCeO+FR2R+2WXt7JxQEv1tDZ6xCS/CTMdibszn&lt;br /&gt;
 fQqlEMj6qNdLh7ymM8umqFlfPx8xRTom8ClkhJryDpV3yYiz380aOt3SCzee68GOwXyM98+P&lt;br /&gt;
 GD9QSzlhxjh6GF5bhW4jEH5uLByjIUQNDIBDvuqSIWWnBE39zoGqvlAlO9ZOtYaHprCREBkF&lt;br /&gt;
 IQHiHqOLMkzBHkHJOrqmROkDXpUSeso1rQZEo/13axZyu4JCgHEGONhCDrzZWjK2ASPQZzjL&lt;br /&gt;
 dAKkuvfIJlwS0yctYWcaK6ttPLyteujWjHbfvJRT6BRLlr0YnmSZs86xWpYnXMrG9xa886Us&lt;br /&gt;
 kswQd7c2QZuBpLgHW3KzrFvCd/LKp3UvPiVUigK6Xgoi7xwwxfv8O4EeZYO2U35w5SPlg+Mz&lt;br /&gt;
 FEJVH2whxboMrHZRhLtyPKY0+qqkLP2LxphUAeNRWNOJIXiazTq1/4Y5dVK1zIq6gg2dBMmH&lt;br /&gt;
 PHx8fQAnhphZzsFNBFZ2htYBEAC7NDbfwBKMD8VRlVUxIds4+0SGsRUhwHQJrU0Tn8vzFiRS&lt;br /&gt;
 GBtDuOdAPyt8GDrjh2c2PKno9piQnbojqKGJ0HvGoHzfm9axb0S4CPgGfcIrSjyQIu4+kpCj&lt;br /&gt;
 tatSaxtuvqqpxNBx9ylfubJgTKW96m8K8twbXc6QczMsd6zSt4U5ER8EWrlT1JB+mW+hNuQW&lt;br /&gt;
 4VQ1A6f0JRQqXOA1b23yNW621CfT9r9t4OpDug9vWyGXyQjjLoiMRsGVH5B/37UXn2BS14wh&lt;br /&gt;
 2xLj+eh9V1pN4S1IZVv/k0EdRwn9VC/bSGgTbk6P6oOM7LrV+BM7yQHoFOO5HPb2jJB+ynVu&lt;br /&gt;
 K4/n0Xe/Zcfp2OPAm9qn5Z0lkTSHRxvCMWxxNoAgirzj/KdNnuDVU7SdRulynIcczqj68adV&lt;br /&gt;
 uEyPeu1mwhOTku7eQnlFmGhkD5oJfg/IPdb7OmnpWsFPfyowG/nR7oPAFVkoNfRRqtUpHIM4&lt;br /&gt;
 k+2Xm/lWxYHzlzVF9SzbLWKs3/J9tyVb7xNAlr8gcbwgO8bOwWUiAG6hSMD1yLdox92seRPY&lt;br /&gt;
 mnhOC6PCG3KKqCH7wBZ84Ez0BDqYDqSzq4/PlCnJrMk3ewb/fuGiMF7kgYHThvdZUeyRgUoY&lt;br /&gt;
 yG7i3R3XRFDUiN5m7SyuRUUdgHwznb2e8Pf/IMYtTZh737bgM+mWc/YlJq+cmQARAQABwsFl&lt;br /&gt;
 BBgBCAAPBQJWdobWAhsMBQkJZgGAAAoJEElE8PvYS2x3Ad0QAN/WS9Mc0MdhJi7fqhq5dU4X&lt;br /&gt;
 QfviUMA5CkWboNiOG57OR1C0a4XJcFCDcgmsYRhMYDj4qw7M+z3fcjFJnEwqHHoIhzsvGbDs&lt;br /&gt;
 Dra8QkP188tx+Uzf4wMnEVCVzOuL5ji36OlxegF5wjj5CTtso237hhcI82+xAnqXteA5pJMw&lt;br /&gt;
 DunRmhEkjpJjxkUtr4vyOSzGBmMP3sWGbq0uVbWacxggb1r56+uKrQULVEnCa4P64d8RPKn7&lt;br /&gt;
 Dsn/Pqf7n+nLevBertj5roQNceXeGIpu0k45wVFUtCA9Rc1Y6myNs0aq8Cw5LKTLemI+uT4y&lt;br /&gt;
 Okky89vroZqG/XetHAXxjZGm+kyMbu3ThvIzOSb5+hTfWcTa8zybUvujkfiejfhRDZ9GWjXS&lt;br /&gt;
 iK20nZ8d2WwTqPDOMySozXFUJoT6TqTJ/I7m9vJj2mz+xPRLHaAVVKF7rMP8Gw+6g9uWbHs1&lt;br /&gt;
 SXAZH/CgQTAJwQ+FxWC657Q+bjg11lmjCHpDMxxFnIdqYiIaKjocQzI2SP67Yr94W0trumOR&lt;br /&gt;
 fZm3nietLoSVVkak0z+SBJZ4/S+XbkDmLnUDG3GJq/QCXFAFVv02VS76gvVYaxFuVWOUIuXf&lt;br /&gt;
 SkWKoa6vs12Cx30Hp/BfdftCHH6IuhzXspKK+br9CqDrRZcHzMB42/QPYcDa/BZBzudBXsZd&lt;br /&gt;
 M+CrfDxPMyd7&lt;br /&gt;
Organization: HCC!Hobbynet&lt;br /&gt;
Message-ID: &amp;lt;bc4cc04a-de4c-54f7-37c4-ffb6f589fb4b@hobby.nl&amp;gt;&lt;br /&gt;
Date: Thu, 31 May 2018 21:48:24 +0200&lt;br /&gt;
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101&lt;br /&gt;
 Thunderbird/52.8.0&lt;br /&gt;
MIME-Version: 1.0&lt;br /&gt;
Content-Type: text/plain; charset=utf-8&lt;br /&gt;
Content-Language: nl&lt;br /&gt;
Content-Transfer-Encoding: 7bit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>2A05:F080:0:300:B848:81C0:7F18:AA86</name></author>
	</entry>
	<entry>
		<id>https://wiki.hobby.nl/index.php?title=DKIM&amp;diff=78336</id>
		<title>DKIM</title>
		<link rel="alternate" type="text/html" href="https://wiki.hobby.nl/index.php?title=DKIM&amp;diff=78336"/>
		<updated>2020-04-05T11:01:10Z</updated>

		<summary type="html">&lt;p&gt;2A05:F080:0:300:B848:81C0:7F18:AA86: /* Directory structuur */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;===Inleiding===&lt;br /&gt;
Om minder snel als spammer te worden aangemerkt kan de mail &amp;quot;ge-signed&amp;quot; worden. Hiervoor moet OpenDKIM geinstalleerd worden en een kleine aanpassing aan de postfix configuratie gemaakt worden.&lt;br /&gt;
===Installatie===&lt;br /&gt;
Gebruik zoals altijd apt-get of aptitude om een package te instaleren.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
apt-get install opendkim opendkim-tools&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
===Configuratie===&lt;br /&gt;
De configuratie van OpenDKIM staat in /etc/opendkim.conf en dient er als volgt ui te zien:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# This is a basic configuration that can easily be adapted to suit a standard&lt;br /&gt;
# installation. For more advanced options, see opendkim.conf(5) and/or&lt;br /&gt;
# /usr/share/doc/opendkim/examples/opendkim.conf.sample.&lt;br /&gt;
#&lt;br /&gt;
#Domain                  example.com&lt;br /&gt;
#KeyFile                 /etc/opendkim/201205.private&lt;br /&gt;
#Selector                201205&lt;br /&gt;
#&lt;br /&gt;
# Commonly-used options&lt;br /&gt;
Canonicalization        relaxed/simple&lt;br /&gt;
Mode                    sv&lt;br /&gt;
SubDomains              yes&lt;br /&gt;
# Log to syslog&lt;br /&gt;
Syslog                  yes&lt;br /&gt;
LogWhy                  yes&lt;br /&gt;
# Required to use local socket with MTAs that access the socket as a non-&lt;br /&gt;
# privileged user (e.g. Postfix)&lt;br /&gt;
UMask                   022&lt;br /&gt;
UserID                  opendkim:opendkim&lt;br /&gt;
#&lt;br /&gt;
KeyTable                /etc/opendkim/KeyTable&lt;br /&gt;
SigningTable            /etc/opendkim/SigningTable&lt;br /&gt;
ExternalIgnoreList      /etc/opendkim/TrustedHosts&lt;br /&gt;
InternalHosts           /etc/opendkim/TrustedHosts&lt;br /&gt;
#&lt;br /&gt;
Socket                  inet:8891@localhost&lt;br /&gt;
#EOF&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Voor uitleg over de diverse parameters, kijk bijvoorbeeld op [https://www.digitalocean.com/community/tutorials/how-to-install-and-configure-dkim-with-postfix-on-debian-wheezy deze site].&lt;br /&gt;
&lt;br /&gt;
===Directory structuur===&lt;br /&gt;
Er moet een directory structuur gemaakt worden om trusted hosts, key tables, signing tables en crypto keys op te slaan. Maak daartoe /etc/opendkim aan met daarin de volgende files en directory: &lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@mail-lb1:/etc/opendkim# ls -l&lt;br /&gt;
total 16&lt;br /&gt;
-rw-r--r-- 1 root root   90 May 25 14:23 KeyTable&lt;br /&gt;
-rw-r--r-- 1 root root   38 May 25 14:24 SigningTable&lt;br /&gt;
-rw-r--r-- 1 root root  151 May 28 22:42 TrustedHosts&lt;br /&gt;
drwxr-xr-x 3 root root 4096 May 25 14:26 keys&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
In de directory komen de keys van de domeinen te staan. Een key voor hobby.nl genereer je met dit script zet meteen rechten goed en kopieerd de keys naar mail-lb2:&lt;br /&gt;
   /usr/local/hobbynet/bin/maakopendkim.sh &#039;&#039;&#039;domeinnaam&#039;&#039;&#039;&lt;br /&gt;
Verander vervolgens de owner en group van default.private naar opendkim. Plaats de inhoud van default in de zone file van het domein en update de zone.&lt;br /&gt;
&lt;br /&gt;
===De Postfix kant===&lt;br /&gt;
Tevens moet in /etc/default/opendkim alles uitgecommentarieerd worden en deze regel toegevoegd worden:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
SOCKET=&amp;quot;inet:8891@localhost&amp;quot;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Dit socket dient aan Postfix bekend te worden gemaakt. Voeg de volgende regels aan /etc/postfix/main.cf toe:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#milter tbv dkim&lt;br /&gt;
milter_default_action = accept&lt;br /&gt;
milter_protocol = 6&lt;br /&gt;
smtpd_milters = inet:localhost:8891&lt;br /&gt;
non_smtpd_milters = inet:localhost:8891&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
Hierdoor controleert en zet Postfix nu ook dkim handtekeningen. Vergeet niet Postfix te herstarten.&lt;br /&gt;
===Testen===&lt;br /&gt;
De configuratie kan worden getest door een lege mail te sturen naar &#039;&#039;&#039;check-auth@verifier.port25.com&#039;&#039;&#039;. Als alles werkt zal in de reply &#039;&#039;&#039;DKIM check: pass&#039;&#039;&#039; staan onder &#039;&#039;&#039;Summary of Results&#039;&#039;&#039;. Voor de geïnteresseerde is het hele bericht opgenomen. &lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
==========================================================&lt;br /&gt;
Summary of Results&lt;br /&gt;
==========================================================&lt;br /&gt;
SPF check:          pass&lt;br /&gt;
&amp;quot;iprev&amp;quot; check:      pass&lt;br /&gt;
DKIM check:         pass&lt;br /&gt;
SpamAssassin check: ham&lt;br /&gt;
&lt;br /&gt;
==========================================================&lt;br /&gt;
Details:&lt;br /&gt;
==========================================================&lt;br /&gt;
&lt;br /&gt;
HELO hostname:  mail-lb1.hobby.nl&lt;br /&gt;
Source IP:      212.72.224.72&lt;br /&gt;
mail-from:      rootmail@hobby.nl&lt;br /&gt;
&lt;br /&gt;
----------------------------------------------------------&lt;br /&gt;
SPF check details:&lt;br /&gt;
----------------------------------------------------------&lt;br /&gt;
Result:         pass&lt;br /&gt;
ID(s) verified: smtp.mailfrom=rootmail@hobby.nl&lt;br /&gt;
&lt;br /&gt;
DNS record(s):&lt;br /&gt;
    hobby.nl. 60 IN TXT &amp;quot;v=spf1 ip4:212.72.224.0/21 ip4:95.97.35.96/29 ip4:80.253.112.0/24 ip4:94.232.160.0/24 ip6:2a02:968::/32 -all&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----------------------------------------------------------&lt;br /&gt;
&amp;quot;iprev&amp;quot; check details:&lt;br /&gt;
----------------------------------------------------------&lt;br /&gt;
Result:         pass (matches mail-lb1.hobby.nl)&lt;br /&gt;
ID(s) verified: policy.iprev=212.72.224.72&lt;br /&gt;
&lt;br /&gt;
DNS record(s):&lt;br /&gt;
    72.224.72.212.in-addr.arpa. 60 IN PTR mail-lb1.hobby.nl.&lt;br /&gt;
    mail-lb1.hobby.nl. 60 IN A 212.72.224.72&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----------------------------------------------------------&lt;br /&gt;
DKIM check details:&lt;br /&gt;
----------------------------------------------------------&lt;br /&gt;
Result:         pass (matches From: rootmail@hobby.nl)&lt;br /&gt;
ID(s) verified: header.d=hobby.nl&lt;br /&gt;
&lt;br /&gt;
Canonicalized Headers:&lt;br /&gt;
    reply-to:rootmail@hobby.nl&#039;0D&#039;&#039;0A&#039;&lt;br /&gt;
    to:check-auth@verifier.port25.com&#039;0D&#039;&#039;0A&#039;&lt;br /&gt;
    from:Hobbynet&#039;20&#039;rootmaill&#039;20&#039;&amp;lt;rootmail@hobby.nl&amp;gt;&#039;0D&#039;&#039;0A&#039;&lt;br /&gt;
    subject:test&#039;0D&#039;&#039;0A&#039;&lt;br /&gt;
    date:Thu,&#039;20&#039;31&#039;20&#039;May&#039;20&#039;2018&#039;20&#039;21:48:24&#039;20&#039;+0200&#039;0D&#039;&#039;0A&#039;&lt;br /&gt;
    dkim-signature:v=1;&#039;20&#039;a=rsa-sha256;&#039;20&#039;c=relaxed/simple;&#039;20&#039;d=hobby.nl;&#039;20&#039;s=default;&#039;20&#039;t=1527796105;&#039;20&#039;bh=frcCV1k9oG9oKj3dpUqdJg1PxRT2RSN/XKdLCPjaYaY=;&#039;20&#039;h=Reply-To:To:From:Subject:Date;&#039;20&#039;b=&lt;br /&gt;
&lt;br /&gt;
Canonicalized Body:&lt;br /&gt;
    &#039;0D&#039;&#039;0A&#039;&lt;br /&gt;
    &lt;br /&gt;
&lt;br /&gt;
DNS record(s):&lt;br /&gt;
    default._domainkey.hobby.nl. 60 IN TXT &amp;quot;v=DKIM1; k=rsa; s=email; p=MIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAyHQygiGyUV+o4WTsNIbxfYPyADNedPojfVfn2YrCZJ6WFhBi6RNKKJndqE+VGgtScSI1fkLRCyquVPTGICUAnUbUQL2NbGQNyo0T8wBJy5QTarir10IMue/2QtjaPnDkwa4m35Bl9YKm4SgeaTd7A/OWXsO2BAgCYfiAHsFvK6e6u4zwcD1ZlGH9bSrgm5x6ucHkROq9aV0R0Pr/+SGkT+9Zs1L/TqbX0OvoKmG+raffHVghG8USo1EVWzFSi7gURqP6C8f9HW4HfLnR203C8uJMHSzBvPv5PbM+kc/QTu1AE478a6aZyaUsEhHQQx7OV08crT6UsdyUHQlQpgl8aR+MwAyrEH54AAPzYjfN5KNsZ35flf2/Yj6X5KtGeG0ZVMR2cew1z3SKTFXg+rq+TWF3EqhiD3fzTypSYk5nhKpKpMYtoU7JytF4Xw02fyJpbiVdAGsLqibM+rY+4qp+C/t1HKHVavGePdg5iBE/Y+lOqG6dJvXpWe7JjEz7HfZOz69XN0ryL5/JUzfCpf7lvyJ3LKET4OuBbSwypzNeDX+DaAHb4qdwNFJGq8H0DjFFFagmPQSeHZdX7qTtIiOSbogFXab2Yz9Yw38GedKk9UQPSdCLqdzeFEZWuTXDn/NdRA7PqWuAUxoe68O57Esz4dnyLqB1Xrs74IzTRpLhiSECAwEAAQ==&amp;quot;&lt;br /&gt;
&lt;br /&gt;
Public key used for verification: default._domainkey.hobby.nl (4096 bits)&lt;br /&gt;
&lt;br /&gt;
NOTE: DKIM checking has been performed based on the latest DKIM specs&lt;br /&gt;
(RFC 4871 or draft-ietf-dkim-base-10) and verification may fail for&lt;br /&gt;
older versions.  If you are using Port25&#039;s PowerMTA, you need to use&lt;br /&gt;
version 3.2r11 or later to get a compatible version of DKIM.&lt;br /&gt;
&lt;br /&gt;
----------------------------------------------------------&lt;br /&gt;
SpamAssassin check details:&lt;br /&gt;
----------------------------------------------------------&lt;br /&gt;
SpamAssassin v3.4.0 (2014-02-07)&lt;br /&gt;
&lt;br /&gt;
Result:         ham (-2.0 points, 5.0 required)&lt;br /&gt;
&lt;br /&gt;
 pts rule name              description&lt;br /&gt;
---- ---------------------- --------------------------------------------------&lt;br /&gt;
-0.0 RCVD_IN_DNSWL_NONE     RBL: Sender listed at http://www.dnswl.org/, no&lt;br /&gt;
                            trust&lt;br /&gt;
                            [212.72.224.72 listed in list.dnswl.org]&lt;br /&gt;
-0.0 SPF_PASS               SPF: sender matches SPF record&lt;br /&gt;
-1.9 BAYES_00               BODY: Bayes spam probability is 0 to 1%&lt;br /&gt;
                            [score: 0.0000]&lt;br /&gt;
-0.1 DKIM_VALID_AU          Message has a valid DKIM or DK signature from author&#039;s&lt;br /&gt;
                            domain&lt;br /&gt;
 0.1 DKIM_SIGNED            Message has a DKIM or DK signature, not necessarily valid&lt;br /&gt;
-0.1 DKIM_VALID             Message has at least one valid DKIM or DK signature&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==============================================================&lt;br /&gt;
Explanation of the possible results (based on RFCs 7601, 7208)&lt;br /&gt;
==============================================================&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
DKIM Results&lt;br /&gt;
============&lt;br /&gt;
&lt;br /&gt;
none:  The message was not signed.&lt;br /&gt;
&lt;br /&gt;
pass:  The message was signed, the signature or signatures were&lt;br /&gt;
    acceptable to the ADMD, and the signature(s) passed verification&lt;br /&gt;
    tests.&lt;br /&gt;
&lt;br /&gt;
fail:  The message was signed and the signature or signatures were&lt;br /&gt;
    acceptable to the ADMD, but they failed the verification test(s).&lt;br /&gt;
&lt;br /&gt;
policy:  The message was signed, but some aspect of the signature or&lt;br /&gt;
    signatures was not acceptable to the ADMD.&lt;br /&gt;
&lt;br /&gt;
neutral:  The message was signed, but the signature or signatures&lt;br /&gt;
    contained syntax errors or were not otherwise able to be&lt;br /&gt;
    processed.  This result is also used for other failures not&lt;br /&gt;
    covered elsewhere in this list.&lt;br /&gt;
&lt;br /&gt;
temperror:  The message could not be verified due to some error that&lt;br /&gt;
    is likely transient in nature, such as a temporary inability to&lt;br /&gt;
    retrieve a public key.  A later attempt may produce a final&lt;br /&gt;
    result.&lt;br /&gt;
&lt;br /&gt;
permerror:  The message could not be verified due to some error that&lt;br /&gt;
    is unrecoverable, such as a required header field being absent.  A&lt;br /&gt;
    later attempt is unlikely to produce a final result.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
SPF Results&lt;br /&gt;
===========&lt;br /&gt;
&lt;br /&gt;
none:  Either (a) no syntactically valid DNS domain name was extracted from&lt;br /&gt;
    the SMTP session that could be used as the one to be authorized, or&lt;br /&gt;
    (b) no SPF records were retrieved from the DNS.&lt;br /&gt;
&lt;br /&gt;
neutral:  The ADMD has explicitly stated that it is not asserting whether&lt;br /&gt;
    the IP address is authorized.&lt;br /&gt;
&lt;br /&gt;
pass:  An explicit statement that the client is authorized to inject mail&lt;br /&gt;
    with the given identity.&lt;br /&gt;
&lt;br /&gt;
fail:  An explicit statement that the client is not authorized to use the&lt;br /&gt;
    domain in the given identity.&lt;br /&gt;
&lt;br /&gt;
softfail:  A weak statement by the publishing ADMD that the host is probably&lt;br /&gt;
    not authorized.  It has not published a stronger, more definitive policy&lt;br /&gt;
    that results in a &amp;quot;fail&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
temperror:  The SPF verifier encountered a transient (generally DNS) error&lt;br /&gt;
    while performing the check.  A later retry may succeed without further&lt;br /&gt;
    DNS operator action.&lt;br /&gt;
&lt;br /&gt;
permerror: The domain&#039;s published records could not be correctly interpreted.&lt;br /&gt;
    This signals an error condition that definitely requires DNS operator&lt;br /&gt;
    intervention to be resolved.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;quot;iprev&amp;quot; Results&lt;br /&gt;
===============&lt;br /&gt;
&lt;br /&gt;
pass:  The DNS evaluation succeeded, i.e., the &amp;quot;reverse&amp;quot; and&lt;br /&gt;
    &amp;quot;forward&amp;quot; lookup results were returned and were in agreement.&lt;br /&gt;
&lt;br /&gt;
fail:  The DNS evaluation failed.  In particular, the &amp;quot;reverse&amp;quot; and&lt;br /&gt;
    &amp;quot;forward&amp;quot; lookups each produced results, but they were not in&lt;br /&gt;
    agreement, or the &amp;quot;forward&amp;quot; query completed but produced no&lt;br /&gt;
    result, e.g., a DNS RCODE of 3, commonly known as NXDOMAIN, or an&lt;br /&gt;
    RCODE of 0 (NOERROR) in a reply containing no answers, was&lt;br /&gt;
    returned.&lt;br /&gt;
&lt;br /&gt;
temperror:  The DNS evaluation could not be completed due to some&lt;br /&gt;
    error that is likely transient in nature, such as a temporary DNS&lt;br /&gt;
    error, e.g., a DNS RCODE of 2, commonly known as SERVFAIL, or&lt;br /&gt;
    other error condition resulted.  A later attempt may produce a&lt;br /&gt;
    final result.&lt;br /&gt;
&lt;br /&gt;
permerror:  The DNS evaluation could not be completed because no PTR&lt;br /&gt;
    data are published for the connecting IP address, e.g., a DNS&lt;br /&gt;
    RCODE of 3, commonly known as NXDOMAIN, or an RCODE of 0 (NOERROR)&lt;br /&gt;
    in a reply containing no answers, was returned.  This prevented&lt;br /&gt;
    completion of the evaluation.  A later attempt is unlikely to&lt;br /&gt;
    produce a final result.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==========================================================&lt;br /&gt;
Original Email&lt;br /&gt;
==========================================================&lt;br /&gt;
&lt;br /&gt;
Return-Path: &amp;lt;rootmail@hobby.nl&amp;gt;&lt;br /&gt;
Received: from mail-lb1.hobby.nl (212.72.224.72) by verifier.port25.com id h218om2e8s48 for &amp;lt;check-auth@verifier.port25.com&amp;gt;; Thu, 31 May 2018 19:48:27 +0000 (envelope-from &amp;lt;rootmail@hobby.nl&amp;gt;)&lt;br /&gt;
Authentication-Results: verifier.port25.com; spf=pass  smtp.mailfrom=rootmail@hobby.nl;&lt;br /&gt;
 iprev=pass (matches mail-lb1.hobby.nl)  policy.iprev=212.72.224.72;&lt;br /&gt;
 dkim=pass (matches From: rootmail@hobby.nl)  header.d=hobby.nl&lt;br /&gt;
Received: from localhost (localhost [127.0.0.1])&lt;br /&gt;
	by mail-lb1.hobby.nl (Postfix) with ESMTP id 8396E5FDEA&lt;br /&gt;
	for &amp;lt;check-auth@verifier.port25.com&amp;gt;; Thu, 31 May 2018 21:48:25 +0200 (CEST)&lt;br /&gt;
X-Virus-Scanned: Debian amavisd-new at mail-lb1.hobby.nl&lt;br /&gt;
Received: from mail-lb1.hobby.nl ([127.0.0.1])&lt;br /&gt;
	by localhost (mail-lb1.hobby.nl [127.0.0.1]) (amavisd-new, port 10024)&lt;br /&gt;
	with ESMTP id bnAxJuumS9FK for &amp;lt;check-auth@verifier.port25.com&amp;gt;;&lt;br /&gt;
	Thu, 31 May 2018 21:48:25 +0200 (CEST)&lt;br /&gt;
Received: from [192.168.10.12] (vandenbussche.xs4all.nl [83.163.218.172])&lt;br /&gt;
	(using TLSv1 with cipher ECDHE-RSA-AES128-SHA (128/128 bits))&lt;br /&gt;
	(No client certificate requested)&lt;br /&gt;
	(Authenticated sender: egbert@vandenbussche.nl)&lt;br /&gt;
	by mail-lb1.hobby.nl (Postfix) with ESMTPSA id 51FE55FDE6&lt;br /&gt;
	for &amp;lt;check-auth@verifier.port25.com&amp;gt;; Thu, 31 May 2018 21:48:25 +0200 (CEST)&lt;br /&gt;
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=hobby.nl; s=default;&lt;br /&gt;
	t=1527796105; bh=frcCV1k9oG9oKj3dpUqdJg1PxRT2RSN/XKdLCPjaYaY=;&lt;br /&gt;
	h=Reply-To:To:From:Subject:Date;&lt;br /&gt;
	b=allKIIWMLMVr0ufrCeIkA8T7VF6xZ9PpPDEG80vqoQraDkwa8FAal+ZXhK/Y/nwtO&lt;br /&gt;
	 XYzhEZmOHSYtvTplFppuvXCsbK2q/ZYf881CounLX/w+Ko0ZNIgJwsOz7WX7MJLDXS&lt;br /&gt;
	 cp13/hRVzNYv0LBsI1sz6cXKkNhVxWEShaIjsSW84bQgAAznR0zG9ZYLuVEXm614T0&lt;br /&gt;
	 cz56At+ONbF/8wqBy3rYRBjJ+66xvajO5DfKX94zJErCpvyoiTYCtO5uf0H3sIsiDs&lt;br /&gt;
	 l7a7IUV3Ituzw0+VNpnRP1J3cNxI7j51EGaoUI1w501cCV6f0wC/qbXd9UVHBAl78g&lt;br /&gt;
	 84j+gS4ImtTe9hR3llRnW+2TfuWradddBjUSkX1UiZDORvMkZM+J2pCgFYxU1GXoR+&lt;br /&gt;
	 GHnDPYqW9KDfuVAHUYU6iZ4eDrijS/Y5OBhix1mAX4/XkYaagpbXD9tr/43nNGV3YU&lt;br /&gt;
	 O8S91tFCgik86DfD5b98lxrr61KHb0X/brYF9l8oBvG9L9nuK0g9r90NeLwhmn88dm&lt;br /&gt;
	 Ll4wN0yIHI3yxEQtli6CdZ4H6gJczv6CRp74U/oNyO8PWIm7Nu4grCtWNPXuOzcHjr&lt;br /&gt;
	 FsGPJun8WFVjwVPeKoEOgUTI27g4nfbHkXQEBb9ykQVvVpe44RXbruS81rfKoPThAw&lt;br /&gt;
	 AU/un1L18tPKxUU+jtT2m2hI=&lt;br /&gt;
Reply-To: rootmail@hobby.nl&lt;br /&gt;
To: check-auth@verifier.port25.com&lt;br /&gt;
From: Hobbynet rootmaill &amp;lt;rootmail@hobby.nl&amp;gt;&lt;br /&gt;
Subject: test&lt;br /&gt;
Openpgp: preference=signencrypt&lt;br /&gt;
Autocrypt: addr=rootmail@hobby.nl; prefer-encrypt=mutual; keydata=&lt;br /&gt;
 xsFNBFZ2htYBEADt6zlAySAIrmfb6mRkAPuekeaAM6jIw6n4vdcpGdYi1fL63uZypoh61Ra7&lt;br /&gt;
 lF8SGs3uNhR6EyfJt/54Wsfami+KE4x5nd0dwPAWEwMaruxwKHBmGU1X/895EoRa3aa6PsEc&lt;br /&gt;
 SGyfJplaCscyTneEdsrhtdqKdJi/be8YunhAuYfu1rEaT8FU+hz1itWJJ/YZycscSA8Cb91d&lt;br /&gt;
 w8dUkJamdK0KtaHXOq0pZcJPICtzd0zQIYuouJM1nAjPqQ6GYWu+TebJorWlrHKIzX9WCE1D&lt;br /&gt;
 4wxktMXC+CCwRrV7YLV48ouMuqFejEYvBPjdiIqfxI+vw3bYmtRg0aQ0i3cvadnq6rYS1P6Y&lt;br /&gt;
 nAKk3U1v1Pr83FPUCgTFTpQqHbNJiRDa3tFkVFrY7YtnW4+iHJ8gT2HLOkzpxq/jkhf6gwSQ&lt;br /&gt;
 GgzAf7hepWBUWpKsd501ezVSoza3WQ4laIqvUaYcMGpdeY2vkHASuBulF/QyOk25PBQGVMjL&lt;br /&gt;
 IKovZKIkCp3ghXmYeNjMvtIih3Zh3edH4eekVpP4tgFkdddwguA/yEYYyvFv8KGBvBrQCMzF&lt;br /&gt;
 ghhDRJ6cZL1ewEwuVkGH9qXlM/Gfw4NUo/APuGbbU2PXSxzdxOxbJX2XuRripIsVTVwWKAeb&lt;br /&gt;
 SAitSSFP8B5talGvV3pKooYxAMNa27LRkoZbMjSOVFJ2yeIUHQARAQABzSBFZ2JlcnQgPGVn&lt;br /&gt;
 YmVydEB2YW5kZW5idXNzY2hlLm5sPsLBggQTAQgALAIbIwUJCWYBgAcLCQgHAwIBBhUIAgkK&lt;br /&gt;
 CwQWAgMBAh4BAheABQJWdoj5AhkBAAoJEElE8PvYS2x3wFYP/jy1Ym+6oQDPuHNauYnujpe5&lt;br /&gt;
 DyZOUrPTHdDqg+HjSXzoozeQGeKpIeAZj7ZXSpfGr4mPaPn8gaWxr6ibQAkVYvTZ4MttoqFo&lt;br /&gt;
 cT3ePbUGHnagNcwAZJlcoNJQ6S92YYVWryFn0F8JMUcnQzUaJyUOIaf5pcdJcbA6bPBcMa8X&lt;br /&gt;
 oHSEyD48Dauir7QpsDTurfTooRBZrlLXMkQCeO+FR2R+2WXt7JxQEv1tDZ6xCS/CTMdibszn&lt;br /&gt;
 fQqlEMj6qNdLh7ymM8umqFlfPx8xRTom8ClkhJryDpV3yYiz380aOt3SCzee68GOwXyM98+P&lt;br /&gt;
 GD9QSzlhxjh6GF5bhW4jEH5uLByjIUQNDIBDvuqSIWWnBE39zoGqvlAlO9ZOtYaHprCREBkF&lt;br /&gt;
 IQHiHqOLMkzBHkHJOrqmROkDXpUSeso1rQZEo/13axZyu4JCgHEGONhCDrzZWjK2ASPQZzjL&lt;br /&gt;
 dAKkuvfIJlwS0yctYWcaK6ttPLyteujWjHbfvJRT6BRLlr0YnmSZs86xWpYnXMrG9xa886Us&lt;br /&gt;
 kswQd7c2QZuBpLgHW3KzrFvCd/LKp3UvPiVUigK6Xgoi7xwwxfv8O4EeZYO2U35w5SPlg+Mz&lt;br /&gt;
 FEJVH2whxboMrHZRhLtyPKY0+qqkLP2LxphUAeNRWNOJIXiazTq1/4Y5dVK1zIq6gg2dBMmH&lt;br /&gt;
 PHx8fQAnhphZzsFNBFZ2htYBEAC7NDbfwBKMD8VRlVUxIds4+0SGsRUhwHQJrU0Tn8vzFiRS&lt;br /&gt;
 GBtDuOdAPyt8GDrjh2c2PKno9piQnbojqKGJ0HvGoHzfm9axb0S4CPgGfcIrSjyQIu4+kpCj&lt;br /&gt;
 tatSaxtuvqqpxNBx9ylfubJgTKW96m8K8twbXc6QczMsd6zSt4U5ER8EWrlT1JB+mW+hNuQW&lt;br /&gt;
 4VQ1A6f0JRQqXOA1b23yNW621CfT9r9t4OpDug9vWyGXyQjjLoiMRsGVH5B/37UXn2BS14wh&lt;br /&gt;
 2xLj+eh9V1pN4S1IZVv/k0EdRwn9VC/bSGgTbk6P6oOM7LrV+BM7yQHoFOO5HPb2jJB+ynVu&lt;br /&gt;
 K4/n0Xe/Zcfp2OPAm9qn5Z0lkTSHRxvCMWxxNoAgirzj/KdNnuDVU7SdRulynIcczqj68adV&lt;br /&gt;
 uEyPeu1mwhOTku7eQnlFmGhkD5oJfg/IPdb7OmnpWsFPfyowG/nR7oPAFVkoNfRRqtUpHIM4&lt;br /&gt;
 k+2Xm/lWxYHzlzVF9SzbLWKs3/J9tyVb7xNAlr8gcbwgO8bOwWUiAG6hSMD1yLdox92seRPY&lt;br /&gt;
 mnhOC6PCG3KKqCH7wBZ84Ez0BDqYDqSzq4/PlCnJrMk3ewb/fuGiMF7kgYHThvdZUeyRgUoY&lt;br /&gt;
 yG7i3R3XRFDUiN5m7SyuRUUdgHwznb2e8Pf/IMYtTZh737bgM+mWc/YlJq+cmQARAQABwsFl&lt;br /&gt;
 BBgBCAAPBQJWdobWAhsMBQkJZgGAAAoJEElE8PvYS2x3Ad0QAN/WS9Mc0MdhJi7fqhq5dU4X&lt;br /&gt;
 QfviUMA5CkWboNiOG57OR1C0a4XJcFCDcgmsYRhMYDj4qw7M+z3fcjFJnEwqHHoIhzsvGbDs&lt;br /&gt;
 Dra8QkP188tx+Uzf4wMnEVCVzOuL5ji36OlxegF5wjj5CTtso237hhcI82+xAnqXteA5pJMw&lt;br /&gt;
 DunRmhEkjpJjxkUtr4vyOSzGBmMP3sWGbq0uVbWacxggb1r56+uKrQULVEnCa4P64d8RPKn7&lt;br /&gt;
 Dsn/Pqf7n+nLevBertj5roQNceXeGIpu0k45wVFUtCA9Rc1Y6myNs0aq8Cw5LKTLemI+uT4y&lt;br /&gt;
 Okky89vroZqG/XetHAXxjZGm+kyMbu3ThvIzOSb5+hTfWcTa8zybUvujkfiejfhRDZ9GWjXS&lt;br /&gt;
 iK20nZ8d2WwTqPDOMySozXFUJoT6TqTJ/I7m9vJj2mz+xPRLHaAVVKF7rMP8Gw+6g9uWbHs1&lt;br /&gt;
 SXAZH/CgQTAJwQ+FxWC657Q+bjg11lmjCHpDMxxFnIdqYiIaKjocQzI2SP67Yr94W0trumOR&lt;br /&gt;
 fZm3nietLoSVVkak0z+SBJZ4/S+XbkDmLnUDG3GJq/QCXFAFVv02VS76gvVYaxFuVWOUIuXf&lt;br /&gt;
 SkWKoa6vs12Cx30Hp/BfdftCHH6IuhzXspKK+br9CqDrRZcHzMB42/QPYcDa/BZBzudBXsZd&lt;br /&gt;
 M+CrfDxPMyd7&lt;br /&gt;
Organization: HCC!Hobbynet&lt;br /&gt;
Message-ID: &amp;lt;bc4cc04a-de4c-54f7-37c4-ffb6f589fb4b@hobby.nl&amp;gt;&lt;br /&gt;
Date: Thu, 31 May 2018 21:48:24 +0200&lt;br /&gt;
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101&lt;br /&gt;
 Thunderbird/52.8.0&lt;br /&gt;
MIME-Version: 1.0&lt;br /&gt;
Content-Type: text/plain; charset=utf-8&lt;br /&gt;
Content-Language: nl&lt;br /&gt;
Content-Transfer-Encoding: 7bit&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>2A05:F080:0:300:B848:81C0:7F18:AA86</name></author>
	</entry>
</feed>