Notes:
- All signing is performed with the example RSA key from RFC 8463.
- This server does not do DNS lookups. By default, the example RSA key from RFC 8463 is used for all domains and selectors. Contact the owner if you'd like a different public key registered.
- DKIM1 verification is performed to identify potential issues with the input format.
- Generated DKIM2 signatures will have a dbg_builtin_h tag that enumerates the mandatory headers and their order, because this has not been fully specified yet.
- Generated DKIM2 signatures will always include any field that starts with "X-PlzSign-" (case-insensitive) for testing of the h= tag.
TODOs:
- Ed25519 signing is not supported yet
- Validate DKIM2 chain integrity, for example that i=N mf= aligns with i=N-1 rt=