From 1c3fba1ddfcd602084e75a7ad1e02cb4c68c4a47 Mon Sep 17 00:00:00 2001 From: "prompt.ac/@jeffrey" Date: Sun, 13 Sep 2026 23:54:34 -0400 Subject: [PATCH] amail: a DKIM signature that checks out is the sender's domain vouching MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Mail from inside the same Workspace arrives dkim=pass, spf=none, no DMARC line — and was being marked unverified. DKIM alone now suffices as long as nothing failed outright; DMARC passing is still the full word. Co-Authored-By: Claude Fable 5.1 --- lith/mail-inbound.mjs | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/lith/mail-inbound.mjs b/lith/mail-inbound.mjs index e9bd992ad8..016730501b 100644 --- a/lith/mail-inbound.mjs +++ b/lith/mail-inbound.mjs @@ -139,7 +139,13 @@ export function authFrom(parsed) { out[m[1].toLowerCase()] ??= m[2].toLowerCase(); } } - out.verified = out.dmarc === "pass" || (out.spf === "pass" && out.dkim === "pass"); + // DMARC passing is the full word; a DKIM signature that checks out is the + // sender's own domain vouching, which is enough as long as nothing else + // failed outright (mail from inside the same Workspace arrives dkim=pass, + // spf=none, with no DMARC line at all). + out.verified = + out.dmarc === "pass" || + (out.dkim === "pass" && out.spf !== "fail" && out.dmarc !== "fail"); return out; } -- 2.51.2