• Please be aware: Kaspersky Anti-Virus has been deprecated
    With the upgrade to Plesk Obsidian 18.0.64, "Kaspersky Anti-Virus for Servers" will be automatically removed from the servers it is installed on. We recommend that you migrate to Sophos Anti-Virus for Servers.
  • The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.

Issue Bad RSA signature - DKIM fails

Josch

New Pleskian
Hi,

I've searched a lot and need to clarify something.

I have a problem when trying to validate via dkimvalidator.com. I get

Validating Signature​


result = fail
Details: bad RSA signature

I checked, if the TXT record for default._domainkey.example.com is the same on all nameservers, described here:


and the domainkeys are different.

Now I read, that the DNS zones may not be updated. Here is the support article:


I checked

cat /etc/bind/rndc.key

and

cat /etc/named.conf

and the secrets are not the same. Do these both secrets have to be exact the same ones?

In rndc.key I have the following:

Code:
key "rndc-key" {
    algorithm hmac-sha256;
    secret "some-long-secret-key-with-44-digits";
};

and in named.conf I have

Code:
key "rndc-key" {
    algorithm hmac-md5;
    secret "another-secret-key-with-24-digits";
};

Could that be the cause of my problem?

Any help is appreciated.

Thanks in advance and regards

Josch
 
Back
Top