PowerShell
PowerShell
Create a DKIM-Signature for a MIME Message
See more DKIM / DomainKey Examples
Demonstrates the Chilkat Dkim.DkimSign method, which creates a DKIM-Signature header and prepends it to a complete MIME message held in a BinData, modifying it in place. The DkimAlg, DkimCanon, DkimDomain, DkimSelector, DkimHeaders, and DkimBodyLengthCount properties configure the generated signature.
Note: The file paths are relative to the application's current working directory. Absolute paths may also be used. Supply the paths appropriate to your own environment.
Background: The signature is computed over a hash of the body plus a chosen set of headers, so the message must be completely built — every header, encoding, and boundary — before signing; any later change invalidates it. The
d= (domain) and s= (selector) tags tell a verifier where to find the public key: at selector._domainkey.domain in DNS. relaxed/relaxed canonicalization tolerates the minor whitespace changes mail systems make in transit, which is why it is the common choice.Chilkat PowerShell Downloads
Add-Type -Path "C:\chilkat\ChilkatDotNet47-x64\ChilkatDotNet47.dll"
$success = $false
# Demonstrates the Dkim.DkimSign method, which creates a DKIM-Signature header and prepends it to
# a complete MIME message. The only argument is a BinData holding the MIME, which is modified in
# place.
#
# The DkimAlg, DkimCanon, DkimDomain, DkimSelector, DkimHeaders, and DkimBodyLengthCount
# properties configure the signature that is generated.
$dkim = New-Object Chilkat.Dkim
# Configure the DKIM signature.
$dkim.DkimDomain = "example.com"
$dkim.DkimSelector = "myselector"
# Signing algorithm written to the a= tag.
$dkim.DkimAlg = "rsa-sha256"
# Canonicalization for headers and body, written to the c= tag.
$dkim.DkimCanon = "relaxed/relaxed"
# Colon-separated list of header fields to sign, written to the h= tag.
$dkim.DkimHeaders = "From:To:Subject:Date:Message-ID"
# Maximum number of canonicalized body bytes to hash. 0 means the entire body.
$dkim.DkimBodyLengthCount = 0
# Load the RSA private key and give it to the Dkim object.
$privKey = New-Object Chilkat.PrivateKey
$success = $privKey.LoadPemFile("qa_data/dkim_private.pem")
if ($success -eq $false) {
$($privKey.LastErrorText)
exit
}
$success = $dkim.SetDkimPrivateKey($privKey)
if ($success -eq $false) {
$($dkim.LastErrorText)
exit
}
# Load the complete MIME message to be signed. It must already contain all headers, transfer
# encodings, MIME boundaries, and body bytes.
$mimeData = New-Object Chilkat.BinData
$success = $mimeData.LoadFile("qa_data/message.eml")
if ($success -eq $false) {
$($mimeData.LastErrorText)
exit
}
# Sign. The DKIM-Signature header is prepended to the MIME in place.
$success = $dkim.DkimSign($mimeData)
if ($success -eq $false) {
$($dkim.LastErrorText)
exit
}
# Save the signed message.
$success = $mimeData.WriteFile("qa_output/signed.eml")
if ($success -eq $false) {
$($mimeData.LastErrorText)
exit
}
$("Message signed.")