Skip to Content.
Sympa Menu

devel - [devel@sympa] DKIM2 support for Sympa

Subject: Developers of Sympa

List archive

Chronological Thread  
  • From: "Bron Gondwana" <address@concealed>
  • To: address@concealed
  • Subject: [devel@sympa] DKIM2 support for Sympa
  • Date: Sun, 04 Oct 2026 15:41:12 -0400

Greetings,

This is my first time posting to this list.  I'm one of the authors on the DKIM2 spec, and I'm keen to have Sympa support DKIM2 even in the early drafts.

I've been working on DKIM2 support for Sympa for a little while, there's a patched copy running on sympa.dkim2.com with my patches, plus the dkim2 branch on my fork at https://github.com/brong/sympa/

DKIM2

The IETF DKIM working group is working on DKIM2, a replacement for DKIM and ARC.  At this stage, the working group believes that the draft specification at https://datatracker.ietf.org/doc/draft-ietf-dkim-dkim2-spec/ is in a fit state for interoperability testing.

DKIM2 has three important new properties:
  • Envelope addresses are signed (fixes DKIM replay); at every hop
  • Envelope from aligns with signing domain (fixes backscatter)
  • Changes are reversible and described by a recipe (not need to trust intermediates, you can verify
The proposed changes to Sympa in order to support DKIM2 are focused very much on the last one, the recipes.  Since you have to describe the changes you are making, it is sensible to make the minimum possible changes!

To this end, there are a couple of pre-cursor changes.  I'm just pasting the commit message here, since it describes what's involved pretty well.  It think these are good changes regardless of DKIM2.

Preserve the body encoding when decorating

    A DKIM2 Message-Instance Recipe is compact only when the lines of the
    original body survive decoration byte for byte. Four changes to
    Sympa::Message keep them that way:

    - Skip the decode/re-encode cycle when personalize_text() substituted
      nothing: base64 and quoted-printable are not canonical, and re-encoding
      unchanged content changes bytes for no reason.
    - Prefer the original charset when re-encoding a personalized or
      decorated body, falling back to UTF-8 only when the new content cannot
      be represented in it, so the Content-Transfer-Encoding stays put.
    - When an inline footer append fails, add the footer as a separate MIME
      part instead of dropping it, leaving the original body part untouched.
    - Quoted-printable bodies get the footer appended at the encoded level
      so only the footer lines are new; base64 bodies are re-wrapped at the
      sender's original line length by diffing the flat base64 with
      Algorithm::Diff, so only the last line and the footer change.

    These apply whether or not Message-Instance headers are enabled; they
    also make classic DKIM signatures over the body more likely to survive.

diffstat
 Message.pm |  243 +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++--------
 1 file changed, 234 insertions(+), 9 deletions(-)

Then of course there's the DKIM2 changes themselves, which track what was edited and build a "Message-Instance" header describing the changes, this is a bigger set of code changes:

 DKIM2-MESSAGE-INSTANCE.md                |  334 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
 Makefile.am                              |    1
 src/lib/Sympa/Message.pm                 |  168 +++++++++++++++++++++++++++++++++++++
 src/lib/Sympa/Spindle/ProcessIncoming.pm |   10 ++
 src/lib/Sympa/Spindle/ProcessOutgoing.pm |   12 ++
 src/lib/Sympa/Spindle/ResendArchive.pm   |   15 +++
 src/lib/Sympa/Spindle/ToList.pm          |    7 +
 src/lib/Sympa/Spindle/ToMailer.pm        |    7 +
 src/lib/Sympa/Spool/Outgoing.pm          |   40 ++++++++
 t/Message_DKIM2.t                        |  737 +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
 10 files changed, 1328 insertions(+), 3 deletions(-)
I
t's mostly just a couple of hook locations for the changes, and a new file which calculates the message-instance.  Plus a chunk of tests.

NOTE: this is largely Claude's work, with me guiding the output and reviewing the shape, but not the raw code itself.  I'm prepared to spend more time on human review and making this high quality if the project is willing to take my work on it.  I'm an experience Perl developer.

Cheers,

Bron.

--
  Bron Gondwana, CEO, Fastmail Pty Ltd / Fastmail US LLC
  address@concealed



  • [devel@sympa] DKIM2 support for Sympa, Bron Gondwana, 10/04/2026

Archive powered by MHonArc 2.6.19+.

Top of Page