Sample code for 30+ languages & platforms
Objective-C

Verify DomainKey-Signature Headers in Downloaded Email

See more DKIM / DomainKey Examples

Downloads email from an IMAP server and verifies the DomainKey-Signature header(s) in each email, if present.

Note: DKIM-Signatures are much more common than DomainKey-Signatures. See the other Chilkat example for verifying DKIM-Signatures (link in the code below).

Chilkat Objective-C Downloads

Objective-C
#import <CkoImap.h>
#import <CkoDkim.h>
#import <CkoJsonObject.h>
#import <CkoBinData.h>

BOOL success = NO;

// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.

CkoImap *imap = [[CkoImap alloc] init];

// Connect to an IMAP server, login, select mailbox..
// Use TLS 
imap.Ssl = YES;
imap.Port = [NSNumber numberWithInt:993];
success = [imap Connect: @"imap.example.com"];
if (success == YES) {
    success = [imap Login: @"myLogin" password: @"myPassword"];
    if (success == YES) {
        success = [imap SelectMailbox: @"Inbox"];
    }

}

if (success != YES) {
    NSLog(@"%@",imap.LastErrorText);
    return;
}

// Note: DKIM-Signatures are much more common than DomainKey-Signature
// See DKIM-Signature Verify Sample.

CkoDkim *dkim = [[CkoDkim alloc] init];

// Download a max of 10 emails and verify any DomainKey-Signature headers
// that are present.

// Download emails by sequence numbers (not UIDs).
BOOL bUid = NO;
int seqNum;
int j;
int n = [imap.NumMessages intValue];
if (n > 50) {
    n = 50;
}

CkoJsonObject *json = [[CkoJsonObject alloc] init];
json.EmitCompact = NO;

// To verify DomainKey-Signature headers, we need the exact unmodified MIME bytes of each email.
CkoBinData *mimeData = [[CkoBinData alloc] init];
seqNum = 1;
while (seqNum <= n) {
    // The FetchSingleBd method was introduced in v9.5.0.76
    success = [imap FetchSingleBd: seqNum bUid: bUid mimeData: mimeData];
    if (success != YES) {
        NSLog(@"%@",imap.LastErrorText);
        return;
    }

    // Note: DKIM-Signatures are much more common than DomainKey-Signature
    // See DKIM-Signature Verify Sample.

    // Get the number of DomainKey-Signature headers.
    int numSigs = [[dkim NumDomainKeySigs: mimeData] intValue];

    // Verify each..
    j = 0;
    while (j < numSigs) {
        NSLog(@"%@%d",@"------ DomainKey Signature ",j);

        success = [dkim DomainKeyVerify: [NSNumber numberWithInt: j] mimeData: mimeData];
        if (success != YES) {
            NSLog(@"%@",@"Not valid.");
            NSLog(@"%@",dkim.LastErrorText);
        }
        else {
            NSLog(@"%@",@"valid.");
        }

        // Show the additional information about the signature verification
        [json Load: dkim.VerifyInfo];
        NSLog(@"%@",[json Emit]);

        // The JSON contains information such as this:

        // 	{
        // 	  "domain": "amazonses.com",
        // 	  "selector": "7v7vs6w47njt4pimodk5mmttbegzsi6n",
        // 	  "publicKey": "MIGfMA0GCSqG...v2GvWPqGHz6uqeQIDAQAB",
        // 	  "canonicalization": "relaxed/simple",
        // 	  "algorithm": "rsa-sha256",
        // 	  "signedHeaders": "Subject:From:To:Date:Mime-Version:Content-Type:References:Message-Id:Feedback-ID",
        // 	  "verified": "yes"
        // 	}

        j = j + 1;
    }

    seqNum = seqNum + 1;
}

success = [imap Disconnect];