Mail deliverability¶
Diagnosis and operating discipline for self-hosted outbound mail. These are the failure modes inherent to running your own MTA — independent of any one deployment.
"No complaints" is not evidence that DKIM is signing¶
DKIM signing and inbound acceptance are independent. With relaxed DMARC alignment, SPF
or DKIM passing is enough to clear inbound checks — so outbound mail can go unsigned for
months with a fully-configured signer, a published DKIM record, and zero complaints. After
any DKIM change, and periodically regardless, probe the actual signature end-to-end (send to
a public DKIM checker such as check-auth@verifier.port25.com, and cross-check a modern
mailbox's Authentication-Results: header). Never infer signing health from the inbox.
Old bundled DKIM signer images can emit malformed Ed25519 signatures
A dated milter image can format the Ed25519 DKIM-Signature in a way strict verifiers
reject as a syntax error while lenient ones pass — a signature that verifies in one place
and fails in another. Until your signer image is current, RSA-2048 is the safe default;
it's verified cleanly by every DKIM verifier. Verify a rotation at two independent
verifiers, since a single one can mask either an unsupported-algorithm or a malformed-header
failure.
Give DKIM selectors at least one non-digit character
A purely numeric selector can be re-typed as a number by YAML/templating and rendered in
scientific notation downstream, silently breaking the DNS lookup (permerror
everywhere). Including one non-digit character anywhere in the selector (e.g. a -rsa
suffix or a month abbreviation) defeats numeric type-coercion entirely — cheap insurance
independent of any templating fix.
Rotate by adding a new selector, not by swapping the key in place¶
Prefer selector rotation (publish a new selector's key in DNS, switch the signer to it, retire the old record a day later) over an in-place key swap. Selector rotation is zero-gap and cleanly rollback-able — the old selector's DNS record is untouched, so reverting the signer restores signing immediately; an in-place swap leaves a window (up to the record's TTL) where recipients holding the cached old key reject new signatures.
Shared-secret rotations must converge across all consumers¶
A shared secret used by both a validator and the parties it authenticates (e.g. a TURN
shared secret used by the TURN server and by the media clients) must be rolled to every
holder together. While they disagree, new allocations fail auth (401); existing sessions,
already validated, stay up. Restart every consumer to close the window, and verify
functionally (place a real call) rather than trusting the sync.
See also: Operations · Identity & access federation.