|
|
|
|
|
by Natsu
2065 days ago
|
|
I really want to see the actual texts so we can do DKIM validation and not have to take anyone's word for it. It looks like Gmail has used the same key since 2016, so this should be possible. dig +short 20161025._domainkey.gmail.com txt
"k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAviPGBk4
ZB64UfSqWyAicdR7lodhytae+EYRQVtKDhM+1mXjEqRtP/
pDT3sBhazkmA48n2k5NJUyMEoO8nc2r6sUA+/Dom5jRBZp6qDKJOwjJ5R/
OpHamlRG+YRJQqR" "tqEgSiJWG7h7efGYWmh4URhFM9k9+rmG/CwCgwx7Et+c8OMlngaLl04
/bPmfpjdEyLWyNimk761CX6KymzYiRDNz1MOJOJ7OzFaS4PFbV
Ln0m5mf0HVNtBpPwWuCNvaFVflUYxEyblbB6h/oWOPGbzoSgtRA47
SHV53SwZjIsVpbq4LxUW9IxAEwYzGcSgZ4n5Q8X8TndowsDUzoccPFGhdwIDAQAB"
I heard claims that someone at ErrataSec has the emails and did this validation, but I want to do it myself. |
|
https://github.com/robertdavidgraham/hunter-dkim