GFI Software

Welcome to the GFI Software community forum! For support please open a ticket from https://support.gfi.com.

Home » GFI User Forums » Kerio Connect » "DKIM Public Key for Domain is Wrong" Error
"DKIM Public Key for Domain is Wrong" Error [message #149438] Sun, 28 February 2021 15:15 Go to next message
Arty13 is currently offline  Arty13
Messages: 2
Registered: February 2021
Hi There,
I've been struggling to get DKIM working on Kerio Connect. My PTR, SPF and DMARC records are good, and my DKIM record is in place (tested by MXtoolbox and dmarcian), but when I ask Kerio to sign my outgoing messages, it gives me the DKIM public key is wrong error. I have copy/pasted exactly what should be in the DKIM DNS record. Any ideas on what is going on?
Thank you.
Re: "DKIM Public Key for Domain is Wrong" Error [message #149440 is a reply to message #149438] Mon, 01 March 2021 03:51 Go to previous messageGo to next message
Nick.Geary is currently offline  Nick.Geary
Messages: 73
Registered: January 2021
In some cases the issue is related to local DNS. Try using the following command and compare the results to those when specifying an external DNS server.

Example: nslookup -q=TXT _dmarc.yourdomain.com vs nslookup -q=TXT _dmarc.yourdomain.com 8.8.8.8


Nick Geary
GFI Software
Re: "DKIM Public Key for Domain is Wrong" Error [message #149444 is a reply to message #149440] Mon, 01 March 2021 16:16 Go to previous messageGo to next message
Arty13 is currently offline  Arty13
Messages: 2
Registered: February 2021
Problem solved... finally.

I'm using Windows Server 2019 and I followed the instructions to set up all of my external DNS TXT records on my local DNS server. That worked fine except for the DKIM record which in the Windows Server DNS service management tool was truncating the entry at 146 characters (couldn't copy/paste the full DKIM public key in a single line of the text field).

The solution was to enter the DKIM public key on multiple rows of no more than 146 characters... i.e. just hit enter in the text entry field and copy/paste the next 146 characters. When I nslookup the domainkey record, it appears as multiple rows in quotations. But it worked!! This is yet another "Bill Gates strikes again" moment for Microsoft... can't believe this nonsense in the latest version of their very expensive server OS.
Re: "DKIM Public Key for Domain is Wrong" Error [message #149452 is a reply to message #149438] Wed, 03 March 2021 15:48 Go to previous message
freakinvibe is currently offline  freakinvibe
Messages: 588
Registered: April 2004
The problem of TXT records for DKIM being too long is quite common, not only with MS DNS:

https://support.pagely.com/hc/en-us/articles/115003387991-Ad ding-DKIM-Records-With-Long-Values

The only solution is to break them into lines like you described.


Dexion Services AG - IT Support Services in Basel, Switzerland
https://dexionag.ch
Previous Topic: Reasonable number of simultaneous connections
Next Topic: Reduce mailbox size
Goto Forum:
  


Current Time: Wed Nov 30 17:30:45 CET 2022

Total time taken to generate the page: 0.05061 seconds