Changes for version 0.17 - 2026-10-08
- Mail::DKIM2::Gate: when the Gate runs the Verifier itself and it passes, the Verifier has already walked the whole Message-Instance chain, so the Gate no longer walks it a second time. It still does when there are no signatures, when the caller supplied VerifyResult, or when the Verifier did not pass.
- The Gate's null-body refusal now names the library option (AllowNullBodyRecipe), not the CLI flag. dkim2sign and dkim2-milter still show --allow-null-body-recipe, and the authentication_milter DKIM2Sign handler shows allow_null_body_recipe.
- authentication_milter DKIM2Verify: for a message that already has Message-Instance headers, skip the MessageInstance verify that only picked the snapshot key when snapshot_directory is not set.
Documentation
Standalone DKIM2 milter for Postfix
Modules
DKIM2 signing and verification for email
Canonicalization, hashing, folding and key handling for DKIM2
DKIM2-signed Delivery Status Notifications
decide whether a front end may sign a message
Streaming message parser base for Signer and Verifier
Compute, verify and undo Message-Instance headers
Keep message snapshots keyed by Message-Instance
verify-and-reflect DKIM2 demonstration logic for dkim2.com
One DKIM2-Signature header, parsed or under construction
Sign a message with a DKIM2-Signature header
Bcc-safe recipient grouping before DKIM2 signing
The tag=value list a DKIM2 header is made of
structured per-level DKIM2 and Message-Instance report
Verify the DKIM2-Signature chain on a message
Handler class for DKIM2 signing
Handler class for DKIM2 signature verification