-
- dkim_private_key = ${extract {${length_3:$dkim_selector}} {\
- ses=dkim512.private \
- sel=dkim.private \
- sed=dkim_ed25519.private \
- }{DDIR/$value}}
-
-.ifndef HEADERS_MAXSIZE
- dkim_sign_headers = OPT
-.else
- dkim_identity = allheaders@$dkim_domain
+.ifdef OPTION
+ warn condition = ${if eq {$dkim_algo}{rsa-sha1}}
+ condition = ${if eq {$dkim_verify_status}{pass}}
+ logwrite = NOTE: forcing dkim verify fail (was pass)
+ set dkim_verify_status = fail
+ set dkim_verify_reason = hash too weak