Pascal (Lazarus/Delphi)
Pascal (Lazarus/Delphi)
Create a DKIM-Signature for a MIME Message
See more DKIM / DomainKey Examples
Demonstrates the Chilkat Dkim.DkimSign method, which creates a DKIM-Signature header and prepends it to a complete MIME message held in a BinData, modifying it in place. The DkimAlg, DkimCanon, DkimDomain, DkimSelector, DkimHeaders, and DkimBodyLengthCount properties configure the generated signature.
Note: The file paths are relative to the application's current working directory. Absolute paths may also be used. Supply the paths appropriate to your own environment.
Background: The signature is computed over a hash of the body plus a chosen set of headers, so the message must be completely built — every header, encoding, and boundary — before signing; any later change invalidates it. The
d= (domain) and s= (selector) tags tell a verifier where to find the public key: at selector._domainkey.domain in DNS. relaxed/relaxed canonicalization tolerates the minor whitespace changes mail systems make in transit, which is why it is the common choice.Chilkat Pascal (Lazarus/Delphi) Downloads
program ChilkatDemo;
// Demonstrates using the Chilkat Pascal wrapper via the C bridge DLL.
// Builds as a console application under Lazarus (FPC) or Delphi.
{$IFDEF FPC}
{$MODE DELPHI}
{$ENDIF}
{$APPTYPE CONSOLE}
uses
{$IFDEF UNIX}
cthreads,
{$ENDIF}
SysUtils,
CkDllLoader,
Chilkat.BinData,
Chilkat.PrivateKey,
Chilkat.Dkim;
// ---------------------------------------------------------------------------
procedure RunDemo;
var
success: Boolean;
dkim: TDkim;
privKey: TPrivateKey;
mimeData: TBinData;
begin
success := False;
// Demonstrates the Dkim.DkimSign method, which creates a DKIM-Signature header and prepends it to
// a complete MIME message. The only argument is a BinData holding the MIME, which is modified in
// place.
//
// The DkimAlg, DkimCanon, DkimDomain, DkimSelector, DkimHeaders, and DkimBodyLengthCount
// properties configure the signature that is generated.
dkim := TDkim.Create;
// Configure the DKIM signature.
dkim.DkimDomain := 'example.com';
dkim.DkimSelector := 'myselector';
// Signing algorithm written to the a= tag.
dkim.DkimAlg := 'rsa-sha256';
// Canonicalization for headers and body, written to the c= tag.
dkim.DkimCanon := 'relaxed/relaxed';
// Colon-separated list of header fields to sign, written to the h= tag.
dkim.DkimHeaders := 'From:To:Subject:Date:Message-ID';
// Maximum number of canonicalized body bytes to hash. 0 means the entire body.
dkim.DkimBodyLengthCount := 0;
// Load the RSA private key and give it to the Dkim object.
privKey := TPrivateKey.Create;
success := privKey.LoadPemFile('qa_data/dkim_private.pem');
if (success = False) then
begin
WriteLn(privKey.LastErrorText);
Exit;
end;
success := dkim.SetDkimPrivateKey(privKey);
if (success = False) then
begin
WriteLn(dkim.LastErrorText);
Exit;
end;
// Load the complete MIME message to be signed. It must already contain all headers, transfer
// encodings, MIME boundaries, and body bytes.
mimeData := TBinData.Create;
success := mimeData.LoadFile('qa_data/message.eml');
if (success = False) then
begin
WriteLn(mimeData.LastErrorText);
Exit;
end;
// Sign. The DKIM-Signature header is prepended to the MIME in place.
success := dkim.DkimSign(mimeData);
if (success = False) then
begin
WriteLn(dkim.LastErrorText);
Exit;
end;
// Save the signed message.
success := mimeData.WriteFile('qa_output/signed.eml');
if (success = False) then
begin
WriteLn(mimeData.LastErrorText);
Exit;
end;
WriteLn('Message signed.');
dkim.Free;
privKey.Free;
mimeData.Free;
end;
// ---------------------------------------------------------------------------
begin
try
RunDemo;
except
on E: Exception do
WriteLn('Unhandled exception: ', E.ClassName, ': ', E.Message);
end;
WriteLn;
{$IFDEF MSWINDOWS}
WriteLn('Press Enter to exit...');
ReadLn;
{$ENDIF}
end.