Verify DomainKey-Signature Headers in Downloaded Email
See more DKIM / DomainKey Examples
Downloads email from an IMAP server and verifies the DomainKey-Signature header(s) in each email, if present.
Note: DKIM-Signatures are much more common than DomainKey-Signatures. See the other Chilkat example for verifying DKIM-Signatures (link in the code below).
Chilkat Delphi DLL Downloads
uses
Winapi.Windows, Winapi.Messages, System.SysUtils, System.Variants, System.Classes, Vcl.Graphics,
Vcl.Controls, Vcl.Forms, Vcl.Dialogs, Vcl.StdCtrls, BinData, Imap, JsonObject, Dkim;
...
procedure TForm1.Button1Click(Sender: TObject);
var
success: Boolean;
imap: HCkImap;
dkim: HCkDkim;
bUid: Boolean;
seqNum: Integer;
j: Integer;
n: Integer;
json: HCkJsonObject;
mimeData: HCkBinData;
numSigs: Integer;
begin
success := False;
// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.
imap := CkImap_Create();
// Connect to an IMAP server, login, select mailbox..
// Use TLS
CkImap_putSsl(imap,True);
CkImap_putPort(imap,993);
success := CkImap_Connect(imap,'imap.example.com');
if (success = True) then
begin
success := CkImap_Login(imap,'myLogin','myPassword');
if (success = True) then
begin
success := CkImap_SelectMailbox(imap,'Inbox');
end;
end;
if (success <> True) then
begin
Memo1.Lines.Add(CkImap__lastErrorText(imap));
Exit;
end;
// Note: DKIM-Signatures are much more common than DomainKey-Signature
// See DKIM-Signature Verify Sample.
dkim := CkDkim_Create();
// Download a max of 10 emails and verify any DomainKey-Signature headers
// that are present.
// Download emails by sequence numbers (not UIDs).
bUid := False;
n := CkImap_getNumMessages(imap);
if (n > 50) then
begin
n := 50;
end;
json := CkJsonObject_Create();
CkJsonObject_putEmitCompact(json,False);
// To verify DomainKey-Signature headers, we need the exact unmodified MIME bytes of each email.
mimeData := CkBinData_Create();
seqNum := 1;
while seqNum <= n do
begin
// The FetchSingleBd method was introduced in v9.5.0.76
success := CkImap_FetchSingleBd(imap,seqNum,bUid,mimeData);
if (success <> True) then
begin
Memo1.Lines.Add(CkImap__lastErrorText(imap));
Exit;
end;
// Note: DKIM-Signatures are much more common than DomainKey-Signature
// See DKIM-Signature Verify Sample.
// Get the number of DomainKey-Signature headers.
numSigs := CkDkim_NumDomainKeySigs(dkim,mimeData);
// Verify each..
j := 0;
while j < numSigs do
begin
Memo1.Lines.Add('------ DomainKey Signature ' + IntToStr(j));
success := CkDkim_DomainKeyVerify(dkim,j,mimeData);
if (success <> True) then
begin
Memo1.Lines.Add('Not valid.');
Memo1.Lines.Add(CkDkim__lastErrorText(dkim));
end
else
begin
Memo1.Lines.Add('valid.');
end;
// Show the additional information about the signature verification
CkJsonObject_Load(json,CkDkim__verifyInfo(dkim));
Memo1.Lines.Add(CkJsonObject__emit(json));
// The JSON contains information such as this:
// {
// "domain": "amazonses.com",
// "selector": "7v7vs6w47njt4pimodk5mmttbegzsi6n",
// "publicKey": "MIGfMA0GCSqG...v2GvWPqGHz6uqeQIDAQAB",
// "canonicalization": "relaxed/simple",
// "algorithm": "rsa-sha256",
// "signedHeaders": "Subject:From:To:Date:Mime-Version:Content-Type:References:Message-Id:Feedback-ID",
// "verified": "yes"
// }
j := j + 1;
end;
seqNum := seqNum + 1;
end;
success := CkImap_Disconnect(imap);
CkImap_Dispose(imap);
CkDkim_Dispose(dkim);
CkJsonObject_Dispose(json);
CkBinData_Dispose(mimeData);
end;