DKIM multiple mail servers

6,583

You can reuse the same records and keys for the new server. It's best practice to setup new keys and records for each server however; any compromise on a single server leaves the others unaffected.

Share:
6,583

Related videos on Youtube

Chris E.
Author by

Chris E.

Updated on September 18, 2022

Comments

  • Chris E.
    Chris E. almost 2 years

    We currently have a single mail server (RHEL/sendmail) for all mail "mail.example.com". We have added a second mail server "email.example.com". We intend to use this for bulk email, while "mail.example.com" remains for transaction and internal mail.

    We have DKIM set up for "mail.example.com", but I need to set up DKIM for "email.example.com".

    My question is this: Can I use the same TXT record I have for "mail.example.com" for "email.example.com" and modify some DKIM/milter/sendmail settings? Or do I have to create an entirely seperate TXT record and key.

  • Chris E.
    Chris E. almost 13 years
    I guess what I'm confused about is exactly what to do to have the new domain signed. Just add the TXT record to DNS? I'm sure theres something out there about this I just cant' find it.
  • Philip
    Philip almost 13 years
    What does PGP have to do with DKIM? What laptop or desktop are you talking about?
  • Philip
    Philip almost 13 years
    Is the new e-mail server sending for a different domain? Like are e-mails from the original sending for example.com and the new sending for bulk.example.com?
  • Chris E.
    Chris E. almost 13 years
    Oh i see what youre saying, my mistake. Yes, all servers will send mail for example.com, just bulk email comes from email.example.com and internal/transactional from mail.example.com. The two sendmail instances are actually running in the same machine.
  • hostmaster
    hostmaster almost 13 years
    DKIM and PGP are both just a digital signature. I mention PGP just for example.
  • Philip
    Philip almost 13 years
    Ok; you should generate new keys for the new server and a new selector record to put in DNS (see this question for a really quick howto). Pop the record in DNS. Then setup the milter with the new keys and the selector name (the milter is otherwise the exact same as the existing setup).