ARC Signing settings with two outgoing domains - ORF Forums

ARC Signing settings with two outgoing domains RSS Back to forum

1

Hello,

I had a question regarding how to setup ARC Signing in ORF with two outgoing/sending domains. I've read through the help file and already have DKIM setup for both domains so I should have everything I need. My question is since I have two different domains which DKIM key and txt info should I use in ORF?

Thanks
Josh

by Josh 3 months ago
2

@Josh: Hello Josh,

Please note that the ARC signature is not added to outbound emails or emails originating from intranet sources. When enabled, ARC signatures are applied to incoming (external) emails only, which of course includes emails that your mail server may later forward to other external mail addresses.

As of writing this (v6.8.3), you can only use one key-record pair for ARC signing, so I recommend using the DKIM key and DKM public key record that has already been successfully employed. Domain-specific configurations (or "Per-Domain" configurations) are expected to be introduced in the upcoming v6.10 update - ARC Signing included.

If you have further questions, just let me know.

by Daniel Novak (Vamsoft) 3 months ago
(in reply to this post)

3

@Daniel Novak (Vamsoft): Thank you for the information and clarification around when ARC signatures will be applied.

That's good to know about the upcoming feature for per-domain configurations. Both domains I manage have existing DKIM records setup. It may be prudent to just not utilize ARC signatures right now until the per-domain configuration is available in v6.10.

Thanks
Josh

by Josh 3 months ago
(in reply to this post)

4

@Josh: Even if ORF is installed on a forwarder, having ARC set in the email— even with a signatory different from the sending/recipient domain—will not cause any problems. A valid ARC signature in the email can only help email delivery and will not lead to blacklisting. ARC signing becomes particularly valuable when you have servers with ORF or other ARC-aware agents downstream in the email delivery chain.

If, at any point down the line, the email fails authentication checks such as SPF/DKIM/DMARC, having already been validated by a trusted signatory and recorded in the ARC-Authentication-Results header, the authentication results can be reused. This, in turn, can save an email from potential rejection or classification as spam.

by Daniel Novak (Vamsoft) 3 months ago
(in reply to this post)

5

@Daniel Novak (Vamsoft): Again, Thank you for the explanation Daniel! I greatly appreciate it and will enable that feature.

Thanks!

by Josh 3 months ago
(in reply to this post)

New comment

Fill in the form below to add a new comment. All fields are required. If you are a registered user on our site, please sign in first.

It will not be published.
hnp1 | hnp2