December 9, 2024
Настройка DKIM
apt update
apt install opendkim -y apt install opendkim-tools systemctl start opendkim systemctl enable opendkim systemctl status opendkim
Создаем папку opendkim и генерируем ключ:
mkdir /etc/opendkim cd /etc/opendkim opendkim-genkey -s dkimkey -d interesnoe24.ru
ll
chown opendkim:opendkim dkimkey.private
cat dkimkey.txt
dkimkey._domainkey IN TXT ( "v=DKIM1; h=sha256; k=rsa; "
"p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAtuekxPl52X+bVLiwCr5Jvvt5ovahesE85y8UikLOTU0aNgrHe/odMMeUQ9WV8Lsf7qIzqms6G1p71N0iX7Pdj/xKsZKDtiwiAEjSrW7u6UkNwP6RIHzbV7++/mZ/JuIBionx1YXngn1UzoBxAIYDIRrvwx72jR9fXat0sXhYSSUFEOvXogfdDA4whgWSlX6emw6BBLJwfAdJhP"
"5ng898iaRYVybVfrcuVdPhBzyoqS366qJhEIez9sECQr3qBk4c14c64aKwx1UwbMxLK8GXzAp2PUE7QTyxmC/eP5CHJfqnQ3CXOZb9lcm7NCIQKtZprg+o8tuwqFMWtHh4ddrDlQIDAQAB" ) ; ----- DKIM key dkimkey for interesnoe24.ru
dkimkey._domainkey v=DKIM1;p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAtuekxPl52X+bVLiwCr5Jvvt5ovahesE85y8UikLOTU0aNgrHe/odMMeUQ9WV8Lsf7qIzqms6G1p71N0iX7Pdj/xKsZKDtiwiAEjSrW7u6UkNwP6RIHzbV7++/mZ/JuIBionx1YXngn1UzoBxAIYDIRrvwx72jR9fXat0sXhYSSUFEOvXogfdDA4whgWSlX6emw6BBLJwfAdJhP5ng898iaRYVybVfrcuVdPhBzyoqS366qJhEIez9sECQr3qBk4c14c64aKwx1UwbMxLK8GXzAp2PUE7QTyxmC/eP5CHJfqnQ3CXOZb9lcm7NCIQKtZprg+o8tuwqFMWtHh4ddrDlQIDAQ
Идем в настройки днс и добавляем:
dig dkimkey._domainkey.interesnoe24.ru txt
nano /etc/opendkim.conf Syslog yes SyslogSuccess yes LogWhy yes
AutoRestart Yes AutoRestartRate 10/1h SignatureAlgorithm rsa-sha256 ExternalIgnoreList refile:/etc/opendkim/TrustedHosts InternalHosts refile:/etc/opendkim/TrustedHosts KeyTable refile:/etc/opendkim/KeyTable SigningTable refile:/etc/opendkim/SigningTable
Сохраняем и переходим в другой файл и меняем сокет:
nano /etc/default/opendkim
nano /etc/opendkim/TrustedHosts 127.0.0.1 localhost *.interesnoe24.ru
nano /etc/opendkim/KeyTable dkimkey._domainkey.interesnoe24.ru interesnoe24.ru:dkimkey:/etc/opendkim/dkimkey.private
nano /etc/opendkim/SigningTable *@interesnoe24.ru dkimkey._domainkey.interesnoe24.ru
systemctl restart opendkim
nano /etc/postfix/main.cf
milter_protocol = 6 milter_default_action = accept smtpd_milters = inet:127.0.0.1:12345 non_smtpd_milters = inet:127.0.0.1:12345
systemctl restart postfix
Ждем обновления DNS, когда все обновится отправляем тестовое письмо на почту check-auth@verifier.port25.com, обратно получим ответ с нашими настройками.