Sample code for 30+ languages & platforms
Zig

Create a DKIM-Signature for a MIME Message

See more DKIM / DomainKey Examples

Demonstrates the Chilkat Dkim.DkimSign method, which creates a DKIM-Signature header and prepends it to a complete MIME message held in a BinData, modifying it in place. The DkimAlg, DkimCanon, DkimDomain, DkimSelector, DkimHeaders, and DkimBodyLengthCount properties configure the generated signature.

Note: The file paths are relative to the application's current working directory. Absolute paths may also be used. Supply the paths appropriate to your own environment.

Background: The signature is computed over a hash of the body plus a chosen set of headers, so the message must be completely built — every header, encoding, and boundary — before signing; any later change invalidates it. The d= (domain) and s= (selector) tags tell a verifier where to find the public key: at selector._domainkey.domain in DNS. relaxed/relaxed canonicalization tolerates the minor whitespace changes mail systems make in transit, which is why it is the common choice.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // Demonstrates the Dkim.DkimSign method, which creates a DKIM-Signature header and prepends it to
    // a complete MIME message.  The only argument is a BinData holding the MIME, which is modified in
    // place.
    //
    // The DkimAlg, DkimCanon, DkimDomain, DkimSelector, DkimHeaders, and DkimBodyLengthCount
    // properties configure the signature that is generated.

    const dkim = try chilkat.Dkim.init();
    defer dkim.deinit();

    // Configure the DKIM signature.
    dkim.setDkimDomain("example.com");
    dkim.setDkimSelector("myselector");

    // Signing algorithm written to the a= tag.
    dkim.setDkimAlg("rsa-sha256");

    // Canonicalization for headers and body, written to the c= tag.
    dkim.setDkimCanon("relaxed/relaxed");

    // Colon-separated list of header fields to sign, written to the h= tag.
    dkim.setDkimHeaders("From:To:Subject:Date:Message-ID");

    // Maximum number of canonicalized body bytes to hash.  0 means the entire body.
    dkim.setDkimBodyLengthCount(0);

    // Load the RSA private key and give it to the Dkim object.
    const priv_key = try chilkat.PrivateKey.init();
    defer priv_key.deinit();
    priv_key.loadPemFile("qa_data/dkim_private.pem") catch {
        std.debug.print("{s}\n", .{try priv_key.getLastErrorText(alloc)});
        return;
    };

    dkim.setDkimPrivateKey(priv_key) catch {
        std.debug.print("{s}\n", .{try dkim.getLastErrorText(alloc)});
        return;
    };

    // Load the complete MIME message to be signed.  It must already contain all headers, transfer
    // encodings, MIME boundaries, and body bytes.
    const mime_data = try chilkat.BinData.init();
    defer mime_data.deinit();
    mime_data.loadFile("qa_data/message.eml") catch {
        std.debug.print("{s}\n", .{try mime_data.getLastErrorText(alloc)});
        return;
    };

    // Sign.  The DKIM-Signature header is prepended to the MIME in place.
    dkim.dkimSign(mime_data) catch {
        std.debug.print("{s}\n", .{try dkim.getLastErrorText(alloc)});
        return;
    };

    // Save the signed message.
    mime_data.writeFile("qa_output/signed.eml") catch {
        std.debug.print("{s}\n", .{try mime_data.getLastErrorText(alloc)});
        return;
    };

    std.debug.print("Message signed.\n", .{});
}