OpenDKIM Signing Your Domains' Mail For Postfix With Keys Made On The Host
OpenDKIM from EPEL signing your domains' mail for postfix: a 2048-bit key made on the host per domain, the DNS record to publish printed by every run, keys only the opendkim user can read, and postfix's milters extended, not replaced. As installed the package never starts. The live test sends mail through postfix and verifies the signature. Original role, live-tested on Rocky Linux 10.
Verification
Live-testedReally deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.
Conformance
- Static validation (yamllint · ansible-lint)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-10-08 · podman 4.9.3 · ansible 2.21.4 · how we verify
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/ansible-opendkim?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Ansible role 1.0.0, live-tested on IaC Bazaar: [OpenDKIM Signing Your Domains' Mail For Postfix With Keys Made On The Host](https://www.iac-bazaar.com/catalog/ansible-opendkim?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```yaml
# OpenDKIM Signing Your Domains' Mail For Postfix With Keys Made On The Host: https://www.iac-bazaar.com/catalog/ansible-opendkim (download from your IaC Bazaar account)
```Preview:
Documentation
opendkim
OpenDKIM from EPEL signing your domains' mail as postfix sends it: a 2048-bit key made on the host for each domain and selector, the DNS record to publish printed by every run, keys only the opendkim user can read, a socket only postfix can open, and postfix's milters extended rather than replaced. Original role for EL 10, live-tested with podman on Rocky Linux 10.
No download, and no version to pin. EL 10 packages opendkim in EPEL, so the
role installs it by name and takes what the distribution ships: a security
update arrives through dnf, not through a new release of this role. What the
role owns is the configuration and the proof that the service works.
The distribution's unit, our configuration. The role installs opendkim
and opendkim-tools from EPEL, writes /etc/opendkim.conf (checked by
opendkim -n) with its key, signing and trusted-host tables, and enables the
package's opendkim.service, which runs as the opendkim user and listens on
the unix socket /run/opendkim/opendkim.sock (0770, opendkim group).
The package does not start. Its file is verify-only and names
/etc/opendkim/keys/default.private, which nothing on EL 10 creates: the service
exits with status 78 and restarts until systemd gives up (measured). The role
signs (Mode sv) with a key it makes for each domain.
Keys belong to the opendkim user, not its group. postfix must join the
opendkim group to open the socket. A key readable by that group is then readable
by postfix too, and RequireSafeKeys refuses it ("key data is not secure") -
the message is deferred, not sent unsigned. The role writes each key 0600 to
the opendkim user in an opendkim-only directory; opendkim -n would not have
caught the difference, because it never opens a key.
What the live test signs and checks. A message from the example domain is
sent through postfix and arrives with d=example.test; s=mail; the signature is
verified offline against the record the role printed, and a copy with one word
of the body changed fails verification. A message from a domain the role does
not sign arrives unsigned, and a user outside the opendkim group cannot open the
socket. postfix in the test already lists a milter of its own; afterwards it is
still first, with the role's socket after it.
License
Commercial - IaC Bazaar EULA. (c) IaC Bazaar.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Variables
- Test
Related modules
ansible-kafka
Apache Kafka 4 (SHA-512 pinned) on Java 21, one KRaft node on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test creates a topic, produces one message, consumes it back and reads the metadata quorum; the metadata log is formatted once as the service user and the root-owned release tree is run in place. Original role, live-tested on Rocky Linux 10.
ansible-dovecot
Dovecot from AppStream: IMAP for your mail clients and LMTP for your MTA, Maildir in each home, TLS required before any login, a minimum TLS version checked before it lands, and every listener on loopback until you open it. The live test delivers over LMTP, reads the message over IMAPS, and sees a plaintext login from another address refused. Original role, live-tested on Rocky Linux 10.
ansible-gotify
Gotify on EL 10 from the vendor's release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), as a hardened systemd service on loopback with its settings in an EnvironmentFile; the live test creates an application, pushes a message with its token, reads it back as the admin, and sees a wrong password and a bad token refused. Original role, live-tested on Rocky Linux 10.
ansible-postfix-tls
An EL host opens no submission service, so every client sends on port 25 where plaintext is accepted. This role adds 587, which refuses mail until the session is encrypted, and 465, which is TLS from the first byte. Port 25 keeps taking plaintext on purpose and the live test asserts it, because a mail exchanger that demands STARTTLS loses mail. Original role, live-tested on Rocky Linux 10.
ansible-mosquitto-broker
Mosquitto (MQTT) with accounts: the package starts in local-only mode with anonymous clients allowed, no persistence directory and no packet-size limit. This role writes a listener that refuses anonymous and wrong-password clients (proved live), keeps retained messages across restarts, caps packets at 1 MiB, and renders topic ACLs from a list. Original role, live-tested on Rocky Linux 10.
ansible-nats
nats on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then saves a context under a throwaway config home, reads it back, and runs server check connection against a dead port expecting exit 2 and CRITICAL. Pinned. Original role, live-tested on Rocky Linux 10.