
Hello everyone,
I use mailman together with mailcow and have configured my mailing list as follows:
- Anonymous list: Yes
- DMARC mitigation action: Replace From: with list address
- DMARC Mitigate unconditionally: Yes
My problem is that my emails are not being accepted by mailcow (rspamd) with the error SPOOFED_UNAUTH (50.00)
In the out-queue of mailman the headers look like this: [QUOTE] Authentication-Results: <my.mailserv.er>; dkim=none; spf=pass (<my.mailserv.er>: domain of sender@t-online.de designates 194.25.134.81 as permitted sender) smtp.mailfrom=sender@t-online.de; dmarc=pass (policy=none) header.from=t-online.de ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=lists.<list.domain>; s=dkim; t=1757400255; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=zmDaIaGeCj1IT8TuP4aJmXRbfyNHV3LqjIfHveVMS0M=; b=Im4F/mpchty4CJvvcW4ZqxMl0BRNnybjcmkPboUSuodopd7nOXaesj3w6kgIwZkLHn1uHY FOiSSjyfZ8Zu0/w4l4Du5uoij2qDCEYHvGFhEugFizE9HJ71i7x0SzoEVSZ9uve6sqnWaE X8+GqtCE+vf0TLLeKhXKHJaBdltbMSqO+QT0BOlbmOdvmUCy6MIqysocTod9io5/+CQOgd SSvsSdDq00CG1IBUsg0Tm2rSf/L2bpGD3bl7QEBKS2id7NeLFM/Zme/3mkHo0N/u7m47xy XSLS9R0C3Kg/YxHY8ctPt7Yas6fwYfzGAOXRvVJz1eeXSrl8B5vWfzJ8+WrE5Q== ARC-Authentication-Results: i=1; <my.mailserv.er>; dkim=none; spf=pass (<my.mailserv.er>: domain of sender@t-online.de designates 194.25.134.81 as permitted sender) smtp.mailfrom=sender@t-online.de; dmarc=pass (policy=none) header.from=t-online.de ARC-Seal: i=1; s=dkim; d=lists.<list.domain>; t=1757400255; a=rsa-sha256; cv=none; b=yrD6cRE7c/L/v8D76U5Ohn57/MJ7/VsObkzQdAHbFny5DbyEO8pZvM0VCVYA5hUGXqoqoU nnKpEW6/CqvNIZmsS9hKzQQEdO5yIzNnyYjARcW5w5MpAlkMjmH3dQ68mLIS9SUyXUsoXj m1zAeYmdTjZWQOiYanaNJLRuxCWSFQHOpAljZe/lZt+4llNNA01YqirqGBRe6uMaJoebe6 2ubsHTr6VlfTrBrdFqLLSWyRBls+e0JwOd2jGahaQ6/ZIf4l1dOqdaUHSq31RjEDAiofmK IGeKC97iu3r9LiFsjICyi+/yedMGbwSeyyFMzz+cAV7wM84eWfSx2S2kPP1c9Q== [END QUOTE]
When the email arrives at rspamd for verification, the DKIM header is added, but there is also the entry: arc=reject ("signature check failed: fail, {[1] = sig:lists.list.domain:reject}"):
[QUOTE] DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=lists.list.domain; s=dkim; t=1757413251; h=from:reply-to:subject:date:message-id:to:mime-version:content-type: content-transfer-encoding:content-language:list-id:list-help: list-owner:list-unsubscribe:list-subscribe:list-post; bh=jH/b69qzW7O+s5h3yE2MxKTwFLElX7b39ILc9yHGhkc=; b=AApU4mb2iuN9u1lYTrIKIcPnB4jzXDX+8vC+2/WwHC8JvCukiR2Std5k3E10cuAyYFhPVk zn6AWY+s6c6HKslDn0RiO3i9QYRLAY5MESxvj0tKO1dKDMz+A8RdcOf4kdO4hDr0DQBf7v yQLLnLjgK8QpZdW8MrlfxcQpQ9XrlyP2GX+ntFh5vDl7frNPXQfnBMoo+l0DIs6SWQuaFX ikrOiISYKugL8TmWXnGohXiAM84W/JT0lvP/Lmt3NjxlyNsAWpHQz736LphydY4r5/JjHI of99pRcbTvEmkZogthHFaXMOG2sDGxGwlIc3+oIUHoXqyY+VLsBQs8FzjR+eaw== Authentication-Results: <my.mailserv.er>; arc=reject ("signature check failed: fail, {[1] = sig:lists.list.domain:reject}") ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=lists.list.domain; s=dkim; t=1757413249; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=QSqNoTMweT1jo6F77TLHa+Nh7a0n/g9qDOsUTT8KpQ4=; b=rDgMC26uNsyTPgmddqQOiUsJh25KUa69TeMJfekVn5sFOnvhQdoa9LCogRMMKzJomA0wu6 CCdi6jGJpjtJdzB7PQ8UhQbeFiOUy9JNswFxQ+Qk1GXBxgN892C6KL/DiB/VW1j1nL0xOk Tc0BNC1zH1/MG2hB332t6u/rjWO+PtxIznAdcCP29AhO39RWWY/J0c/CHCOoqFYKCEf1ZH J4Wqeu9ANF44cPwopuJzJioWts6JKRvAM5TjnInZ+HaSv5QmuHvdI0fWvh272O3vGfvEPc iG1QsJS9XWpzkymRjYWo6h1c4/eY7eZd4FEzSR/TtW6Ud9b04A5lUmPpEvTxlQ== ARC-Authentication-Results: i=1; <my.mailserv.er>; dkim=none; dmarc=pass (policy=none) header.from=t-online.de; spf=pass (<my.mailserv.er>: domain of sender@t-online.de designates 194.25.134.20 as permitted sender) smtp.mailfrom=sender@t-online.de [END QUOTE]
What am I still doing wrong? Can you help me, which setting is still missing? What informations are you still missing?
Thanks for your help, Matthias