简体   繁体   English


[英]DKIM signing fails with body hash did not verify for Mimekit , Mailkit

I see a strange problem while DKIM signing the headers with Mailkit & Mimekit, Gmail reports the error "dkim=neutral (body hash did not verify)". 当DKIM使用Mailkit和Mimekit对邮件头进行签名时,我看到一个奇怪的问题,Gmail报告了错误“ dkim = neutral(正文哈希未验证)”。

Am I doing something wrong here?.Please find my code below and screenshots 我在这里做错了吗?请在下面找到我的代码和屏幕截图 Gmail图片1 头 of the actual received mail attached. 实际收到的邮件附件。

        string ReturnName = "DMC12";
        string FromDomain = "backtothefuture.net";
        string FromEmail = "marty@" + FromDomain;
        string FromName = "Marty McFly";
        string SenderName = "Marty McFly";
        string ToEmail = "George.mcfly.1960@gmail.com";
        string MailServer = "DMC12.large.timemachine.com";
        string TextBody = @"If you put your mind to it, you can accomplish anything. One other thing. If you guys ever have kids, and one of them, when he's eight years old, accidentally sets fire to the living room rug... go easy on him!";
        string HtmlBody = string.Format(@"<b>如果你把你的头脑,它可以完成任何事情。 另一件事。 如果你们有孩子,其中一个,当他八岁时,不小心把火烧在客厅地毯上...去容易对他!</b>");
        string Subject  = "Message from Marty (1960)!";
        string ToName = "George McFly";
        string DKIMdomain = FromDomain;
        string DKIMSigner = "btfreturns.com";         
        string ReturnEmail = "DocBrown@" + MailServer;
        string SenderEmail = "marty@" + MailServer;
        string privatekey = System.IO.File.ReadAllText("dkim.private.key");
        var client = new SmtpClient(new ProtocolLogger("smtp.txt")); // logging SMTP connections

                client.Connect(MailServer, 25);
            catch (SmtpCommandException ex)
                Console.WriteLine("Error trying to connect: {0}", ex.Message);
                Console.WriteLine("\tStatusCode: {0}", ex.StatusCode);
            catch (SmtpProtocolException ex)
                Console.WriteLine("Protocol error while trying to connect: {0}", ex.Message);
            catch (Exception ex)

            client.LocalDomain = MailServer;

            var message = new MimeMessage();
            MailboxAddress RecepientAddress = new MailboxAddress(ToName, ToEmail);

            message.From.Add(new MailboxAddress(FromName, FromEmail)); // From Address
            var builder = new BodyBuilder();

            builder.TextBody = TextBody;
            builder.HtmlBody = HtmlBody;

            List<MailboxAddress> To = new List<MailboxAddress>();

            message.Subject = Subject;
            message.Body = builder.ToMessageBody();
            message.Sender = new MailboxAddress(SenderName, SenderEmail);  // Sender Address
            message.MessageId = Guid.NewGuid().ToString("N") + "@" + new System.Net.Mail.MailAddress(message.Sender.Address).Host;

                using (Stream s = (new MemoryStream(Encoding.UTF8.GetBytes(privatekey ?? ""))))
                    var headersToSign = new[] { HeaderId.From, HeaderId.To, HeaderId.Subject, HeaderId.Date, HeaderId.MessageId };
                    var signer = new DkimSigner(s, DKIMdomain, DKIMSigner);
                    signer.SignatureAlgorithm = DkimSignatureAlgorithm.RsaSha1;
                    message.Sign(signer, headersToSign, DkimCanonicalizationAlgorithm.Relaxed, DkimCanonicalizationAlgorithm.Relaxed);

                client.Send(message, new MailboxAddress(ReturnName, ReturnEmail), To);              
                client.Connect(MailServer, 25);

The problem is that you are not calling message.Prepare() before DKIM signing the message. 问题是您未在DKIM签名消息之前调用message.Prepare() This is a very important step because it forces all of the MIME parts of the message body into an appropriate encoding to be used for transport. 这是非常重要的一步,因为它会强制将邮件正文的所有MIME部分转换为适当的编码以用于传输。

Note that if you do not call Prepare() with an appropriate encoding constraint value, the SmtpClient.Send() method will end up doing that after you've DKIM signed the message, thus invalidating the signature. 请注意,如果未使用适当的编码约束值调用Prepare() ,则在DKIM对消息进行签名SmtpClient.Send()方法将最终执行此操作,从而使签名无效。

My suggestion is to use EncodingConstraint.SevenBit for maximum interoperability. 我的建议是使用EncodingConstraint.SevenBit以获得最大的互操作性。

However, if you are confidant that your SMTP server and all other SMTP servers that your message will transfer through support the 8BITMIME extension, then you can try using EncodingConstraint.EightBit instead. 但是,如果您确信您的邮件将通过SMTP服务器和所有其他SMTP服务器传输,则支持8BITMIME扩展名,那么您可以尝试使用EncodingConstraint.EightBit

声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.

粤ICP备18138465号  © 2020-2024 STACKOOM.COM