Sample code for 30+ languages & platforms
Rust

Create a DKIM-Signature for a MIME Message

See more DKIM / DomainKey Examples

Demonstrates the Chilkat Dkim.DkimSign method, which creates a DKIM-Signature header and prepends it to a complete MIME message held in a BinData, modifying it in place. The DkimAlg, DkimCanon, DkimDomain, DkimSelector, DkimHeaders, and DkimBodyLengthCount properties configure the generated signature.

Note: The file paths are relative to the application's current working directory. Absolute paths may also be used. Supply the paths appropriate to your own environment.

Background: The signature is computed over a hash of the body plus a chosen set of headers, so the message must be completely built — every header, encoding, and boundary — before signing; any later change invalidates it. The d= (domain) and s= (selector) tags tell a verifier where to find the public key: at selector._domainkey.domain in DNS. relaxed/relaxed canonicalization tolerates the minor whitespace changes mail systems make in transit, which is why it is the common choice.

Chilkat Rust Downloads

Rust

// Demonstrates the Dkim.DkimSign method, which creates a DKIM-Signature header and prepends it to
// a complete MIME message.  The only argument is a BinData holding the MIME, which is modified in
// place.
// 
// The DkimAlg, DkimCanon, DkimDomain, DkimSelector, DkimHeaders, and DkimBodyLengthCount
// properties configure the signature that is generated.

let dkim = chilkat::Dkim::new();

// Configure the DKIM signature.
dkim.set_dkim_domain("example.com");
dkim.set_dkim_selector("myselector");

// Signing algorithm written to the a= tag.
dkim.set_dkim_alg("rsa-sha256");

// Canonicalization for headers and body, written to the c= tag.
dkim.set_dkim_canon("relaxed/relaxed");

// Colon-separated list of header fields to sign, written to the h= tag.
dkim.set_dkim_headers("From:To:Subject:Date:Message-ID");

// Maximum number of canonicalized body bytes to hash.  0 means the entire body.
dkim.set_dkim_body_length_count(0);

// Load the RSA private key and give it to the Dkim object.
let priv_key = chilkat::PrivateKey::new();
if priv_key.load_pem_file("qa_data/dkim_private.pem").is_err() {
    println!("{}", priv_key.last_error_text());
    return;
}

if dkim.set_dkim_private_key(&priv_key).is_err() {
    println!("{}", dkim.last_error_text());
    return;
}

// Load the complete MIME message to be signed.  It must already contain all headers, transfer
// encodings, MIME boundaries, and body bytes.
let mime_data = chilkat::BinData::new();
if mime_data.load_file("qa_data/message.eml").is_err() {
    println!("{}", mime_data.last_error_text());
    return;
}

// Sign.  The DKIM-Signature header is prepended to the MIME in place.
if dkim.dkim_sign(&mime_data).is_err() {
    println!("{}", dkim.last_error_text());
    return;
}

// Save the signed message.
if mime_data.write_file("qa_output/signed.eml").is_err() {
    println!("{}", mime_data.last_error_text());
    return;
}

println!("Message signed.");