OpenDKIM Signing Your Domains' Mail For Postfix With Keys Made On The Host

OpenDKIM from EPEL signing your domains' mail for postfix: a 2048-bit key made on the host per domain, the DNS record to publish printed by every run, keys only the opendkim user can read, and postfix's milters extended, not replaced. As installed the package never starts. The live test sends mail through postfix and verifies the signature. Original role, live-tested on Rocky Linux 10.

ansibleMessaging & Streaming

Verification

Live-tested

Really deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.

Conformance

  • Static validation (yamllint · ansible-lint)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live-tested - applied, verified, destroyed

Last verified 2026-10-08 · podman 4.9.3 · ansible 2.21.4 · how we verify

Cite it in your README

badge · attribution

Paste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.

README.md, GitLab, Gitea
[![IaC Bazaar: live-tested](https://www.iac-bazaar.com/api/artifacts/ansible-opendkim/badge)](https://www.iac-bazaar.com/catalog/ansible-opendkim?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

Ansible role 1.0.0, live-tested on IaC Bazaar: [OpenDKIM Signing Your Domains' Mail For Postfix With Keys Made On The Host](https://www.iac-bazaar.com/catalog/ansible-opendkim?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

```yaml
# OpenDKIM Signing Your Domains' Mail For Postfix With Keys Made On The Host: https://www.iac-bazaar.com/catalog/ansible-opendkim (download from your IaC Bazaar account)
```

Preview:IaC Bazaar: live-tested

Documentation

opendkim

OpenDKIM from EPEL signing your domains' mail as postfix sends it: a 2048-bit key made on the host for each domain and selector, the DNS record to publish printed by every run, keys only the opendkim user can read, a socket only postfix can open, and postfix's milters extended rather than replaced. Original role for EL 10, live-tested with podman on Rocky Linux 10.

No download, and no version to pin. EL 10 packages opendkim in EPEL, so the role installs it by name and takes what the distribution ships: a security update arrives through dnf, not through a new release of this role. What the role owns is the configuration and the proof that the service works.

The distribution's unit, our configuration. The role installs opendkim and opendkim-tools from EPEL, writes /etc/opendkim.conf (checked by opendkim -n) with its key, signing and trusted-host tables, and enables the package's opendkim.service, which runs as the opendkim user and listens on the unix socket /run/opendkim/opendkim.sock (0770, opendkim group).

The package does not start. Its file is verify-only and names /etc/opendkim/keys/default.private, which nothing on EL 10 creates: the service exits with status 78 and restarts until systemd gives up (measured). The role signs (Mode sv) with a key it makes for each domain.

Keys belong to the opendkim user, not its group. postfix must join the opendkim group to open the socket. A key readable by that group is then readable by postfix too, and RequireSafeKeys refuses it ("key data is not secure") - the message is deferred, not sent unsigned. The role writes each key 0600 to the opendkim user in an opendkim-only directory; opendkim -n would not have caught the difference, because it never opens a key.

What the live test signs and checks. A message from the example domain is sent through postfix and arrives with d=example.test; s=mail; the signature is verified offline against the record the role printed, and a copy with one word of the body changed fails verification. A message from a domain the role does not sign arrives unsigned, and a user outside the opendkim group cannot open the socket. postfix in the test already lists a milter of its own; afterwards it is still first, with the role's socket after it.

License

Commercial - IaC Bazaar EULA. (c) IaC Bazaar.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Variables
  • Test

Related modules

Live-tested

ansible-kafka

Apache Kafka 4 (SHA-512 pinned) on Java 21, one KRaft node on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test creates a topic, produces one message, consumes it back and reads the metadata quorum; the metadata log is formatted once as the service user and the root-owned release tree is run in place. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-dovecot

Dovecot from AppStream: IMAP for your mail clients and LMTP for your MTA, Maildir in each home, TLS required before any login, a minimum TLS version checked before it lands, and every listener on loopback until you open it. The live test delivers over LMTP, reads the message over IMAPS, and sees a plaintext login from another address refused. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-gotify

Gotify on EL 10 from the vendor's release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), as a hardened systemd service on loopback with its settings in an EnvironmentFile; the live test creates an application, pushes a message with its token, reads it back as the admin, and sees a wrong password and a bad token refused. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-postfix-tls

An EL host opens no submission service, so every client sends on port 25 where plaintext is accepted. This role adds 587, which refuses mail until the session is encrypted, and 465, which is TLS from the first byte. Port 25 keeps taking plaintext on purpose and the live test asserts it, because a mail exchanger that demands STARTTLS loses mail. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-mosquitto-broker

Mosquitto (MQTT) with accounts: the package starts in local-only mode with anonymous clients allowed, no persistence directory and no packet-size limit. This role writes a listener that refuses anonymous and wrong-password clients (proved live), keeps retained messages across restarts, caps packets at 1 MiB, and renders topic ACLs from a list. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-nats

nats on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then saves a context under a throwaway config home, reads it back, and runs server check connection against a dead port expecting exit 2 and CRITICAL. Pinned. Original role, live-tested on Rocky Linux 10.

View module