Sample code for 30+ languages & platforms
Tcl

Create a DKIM-Signature for a MIME Message

See more DKIM / DomainKey Examples

Demonstrates the Chilkat Dkim.DkimSign method, which creates a DKIM-Signature header and prepends it to a complete MIME message held in a BinData, modifying it in place. The DkimAlg, DkimCanon, DkimDomain, DkimSelector, DkimHeaders, and DkimBodyLengthCount properties configure the generated signature.

Note: The file paths are relative to the application's current working directory. Absolute paths may also be used. Supply the paths appropriate to your own environment.

Background: The signature is computed over a hash of the body plus a chosen set of headers, so the message must be completely built — every header, encoding, and boundary — before signing; any later change invalidates it. The d= (domain) and s= (selector) tags tell a verifier where to find the public key: at selector._domainkey.domain in DNS. relaxed/relaxed canonicalization tolerates the minor whitespace changes mail systems make in transit, which is why it is the common choice.

Chilkat Tcl Downloads

Tcl

load ./chilkat.dll

set success 0

#  Demonstrates the Dkim.DkimSign method, which creates a DKIM-Signature header and prepends it to
#  a complete MIME message.  The only argument is a BinData holding the MIME, which is modified in
#  place.
#  
#  The DkimAlg, DkimCanon, DkimDomain, DkimSelector, DkimHeaders, and DkimBodyLengthCount
#  properties configure the signature that is generated.

set dkim [new_CkDkim]

#  Configure the DKIM signature.
CkDkim_put_DkimDomain $dkim "example.com"
CkDkim_put_DkimSelector $dkim "myselector"

#  Signing algorithm written to the a= tag.
CkDkim_put_DkimAlg $dkim "rsa-sha256"

#  Canonicalization for headers and body, written to the c= tag.
CkDkim_put_DkimCanon $dkim "relaxed/relaxed"

#  Colon-separated list of header fields to sign, written to the h= tag.
CkDkim_put_DkimHeaders $dkim "From:To:Subject:Date:Message-ID"

#  Maximum number of canonicalized body bytes to hash.  0 means the entire body.
CkDkim_put_DkimBodyLengthCount $dkim 0

#  Load the RSA private key and give it to the Dkim object.
set privKey [new_CkPrivateKey]

set success [CkPrivateKey_LoadPemFile $privKey "qa_data/dkim_private.pem"]
if {$success == 0} then {
    puts [CkPrivateKey_lastErrorText $privKey]
    delete_CkDkim $dkim
    delete_CkPrivateKey $privKey
    exit
}

set success [CkDkim_SetDkimPrivateKey $dkim $privKey]
if {$success == 0} then {
    puts [CkDkim_lastErrorText $dkim]
    delete_CkDkim $dkim
    delete_CkPrivateKey $privKey
    exit
}

#  Load the complete MIME message to be signed.  It must already contain all headers, transfer
#  encodings, MIME boundaries, and body bytes.
set mimeData [new_CkBinData]

set success [CkBinData_LoadFile $mimeData "qa_data/message.eml"]
if {$success == 0} then {
    puts [CkBinData_lastErrorText $mimeData]
    delete_CkDkim $dkim
    delete_CkPrivateKey $privKey
    delete_CkBinData $mimeData
    exit
}

#  Sign.  The DKIM-Signature header is prepended to the MIME in place.
set success [CkDkim_DkimSign $dkim $mimeData]
if {$success == 0} then {
    puts [CkDkim_lastErrorText $dkim]
    delete_CkDkim $dkim
    delete_CkPrivateKey $privKey
    delete_CkBinData $mimeData
    exit
}

#  Save the signed message.
set success [CkBinData_WriteFile $mimeData "qa_output/signed.eml"]
if {$success == 0} then {
    puts [CkBinData_lastErrorText $mimeData]
    delete_CkDkim $dkim
    delete_CkPrivateKey $privKey
    delete_CkBinData $mimeData
    exit
}

puts "Message signed."

delete_CkDkim $dkim
delete_CkPrivateKey $privKey
delete_CkBinData $mimeData