Re: Options

From: Murray S. Kucherawy <>
Date: Thu, 26 Nov 2009 09:31:45 -0800 (PST)

On Thu, 26 Nov 2009, Roman Gelfand wrote:
> My topology is dmz. The firewall passes the messages to the postfix
> server in dmz. Since opendkim milter is not going to be the first in
> line, it actually receives mail from postfix server Unless
> you tell me otherwise, I don't want to neither sign nor verify
> Unless it doesn't matter and opendkim is able to discern the
> original message source, how do you tell opendkim to ignore localhost
> hop?

Put in the PeerList. This causes that host to be completely
ignored. The opendkim(8) and opendkim.conf(5) man pages contain
instructions for doing this both from the command line and the
configuration file.

The IP address/hostname of the client is only used when deciding whether
to sign or verify a message. If the injecting IP address always appears
as, you'll have some trouble deciding when to sign and when to
verify safely. How can you determine what's inbound and what's outbound?
