Unicode C
Unicode C
Create a DKIM-Signature for a MIME Message
See more DKIM / DomainKey Examples
Demonstrates the Chilkat Dkim.DkimSign method, which creates a DKIM-Signature header and prepends it to a complete MIME message held in a BinData, modifying it in place. The DkimAlg, DkimCanon, DkimDomain, DkimSelector, DkimHeaders, and DkimBodyLengthCount properties configure the generated signature.
Note: The file paths are relative to the application's current working directory. Absolute paths may also be used. Supply the paths appropriate to your own environment.
Background: The signature is computed over a hash of the body plus a chosen set of headers, so the message must be completely built — every header, encoding, and boundary — before signing; any later change invalidates it. The
d= (domain) and s= (selector) tags tell a verifier where to find the public key: at selector._domainkey.domain in DNS. relaxed/relaxed canonicalization tolerates the minor whitespace changes mail systems make in transit, which is why it is the common choice.Chilkat Unicode C Downloads
#include <C_CkDkimW.h>
#include <C_CkPrivateKeyW.h>
#include <C_CkBinDataW.h>
void ChilkatSample(void)
{
BOOL success;
HCkDkimW dkim;
HCkPrivateKeyW privKey;
HCkBinDataW mimeData;
success = FALSE;
// Demonstrates the Dkim.DkimSign method, which creates a DKIM-Signature header and prepends it to
// a complete MIME message. The only argument is a BinData holding the MIME, which is modified in
// place.
//
// The DkimAlg, DkimCanon, DkimDomain, DkimSelector, DkimHeaders, and DkimBodyLengthCount
// properties configure the signature that is generated.
dkim = CkDkimW_Create();
// Configure the DKIM signature.
CkDkimW_putDkimDomain(dkim,L"example.com");
CkDkimW_putDkimSelector(dkim,L"myselector");
// Signing algorithm written to the a= tag.
CkDkimW_putDkimAlg(dkim,L"rsa-sha256");
// Canonicalization for headers and body, written to the c= tag.
CkDkimW_putDkimCanon(dkim,L"relaxed/relaxed");
// Colon-separated list of header fields to sign, written to the h= tag.
CkDkimW_putDkimHeaders(dkim,L"From:To:Subject:Date:Message-ID");
// Maximum number of canonicalized body bytes to hash. 0 means the entire body.
CkDkimW_putDkimBodyLengthCount(dkim,0);
// Load the RSA private key and give it to the Dkim object.
privKey = CkPrivateKeyW_Create();
success = CkPrivateKeyW_LoadPemFile(privKey,L"qa_data/dkim_private.pem");
if (success == FALSE) {
wprintf(L"%s\n",CkPrivateKeyW_lastErrorText(privKey));
CkDkimW_Dispose(dkim);
CkPrivateKeyW_Dispose(privKey);
return;
}
success = CkDkimW_SetDkimPrivateKey(dkim,privKey);
if (success == FALSE) {
wprintf(L"%s\n",CkDkimW_lastErrorText(dkim));
CkDkimW_Dispose(dkim);
CkPrivateKeyW_Dispose(privKey);
return;
}
// Load the complete MIME message to be signed. It must already contain all headers, transfer
// encodings, MIME boundaries, and body bytes.
mimeData = CkBinDataW_Create();
success = CkBinDataW_LoadFile(mimeData,L"qa_data/message.eml");
if (success == FALSE) {
wprintf(L"%s\n",CkBinDataW_lastErrorText(mimeData));
CkDkimW_Dispose(dkim);
CkPrivateKeyW_Dispose(privKey);
CkBinDataW_Dispose(mimeData);
return;
}
// Sign. The DKIM-Signature header is prepended to the MIME in place.
success = CkDkimW_DkimSign(dkim,mimeData);
if (success == FALSE) {
wprintf(L"%s\n",CkDkimW_lastErrorText(dkim));
CkDkimW_Dispose(dkim);
CkPrivateKeyW_Dispose(privKey);
CkBinDataW_Dispose(mimeData);
return;
}
// Save the signed message.
success = CkBinDataW_WriteFile(mimeData,L"qa_output/signed.eml");
if (success == FALSE) {
wprintf(L"%s\n",CkBinDataW_lastErrorText(mimeData));
CkDkimW_Dispose(dkim);
CkPrivateKeyW_Dispose(privKey);
CkBinDataW_Dispose(mimeData);
return;
}
wprintf(L"Message signed.\n");
CkDkimW_Dispose(dkim);
CkPrivateKeyW_Dispose(privKey);
CkBinDataW_Dispose(mimeData);
}