cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2704
Views
0
Helpful
4
Replies

ESA brakes DKIM

lyutov_dv
Level 1
Level 1

Hello,

When i send an emai from my personal account to my corporate email Cisco ESA can't verify DKIM signature. The message is dkim=hardfail (body hash did not verify [final])

But when i send an email from the personal accont to the Gmail, eveything is OK, Gmail can verify DKIM signature with result "Pass".

What might be a reason?

4 Replies 4

dmccabej
Cisco Employee
Cisco Employee

Hello,

Body hash errors are typical of something modifying the message in transit before it gets to the point of verification. Then, once we try and verify the hash it does not properly match the content from when it was signed.

You may wish to first check if anything is modifying the message prior to it being received on the ESA.

Thanks!

-Dennis M.

Hello,

We use ESA as an EDGE server for SMTP connection, so there is no device that can modify messages...

Hello,

If that's the case then you may wish to open a ticket with TAC. From there we can verify the ESA configuration along with any DKIM headers/signatures/keys/ETC. You may wish to also confirm you're seeing hardfails from other sending domains (different personal accounts) when testing.

Thanks

-Dennis M.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: