Sample code for 30+ languages & platforms
Delphi ActiveX

Verify DomainKey-Signature Headers in Downloaded Email

See more DKIM / DomainKey Examples

Downloads email from an IMAP server and verifies the DomainKey-Signature header(s) in each email, if present.

Note: DKIM-Signatures are much more common than DomainKey-Signatures. See the other Chilkat example for verifying DKIM-Signatures (link in the code below).

Chilkat Delphi ActiveX Downloads

Delphi ActiveX
uses
    Winapi.Windows, Winapi.Messages, System.SysUtils, System.Variants, System.Classes, Vcl.Graphics,
    Vcl.Controls, Vcl.Forms, Vcl.Dialogs, Vcl.StdCtrls, Chilkat_TLB;

...

procedure TForm1.Button1Click(Sender: TObject);
var
success: Integer;
imap: TChilkatImap;
dkim: TChilkatDkim;
bUid: Integer;
seqNum: Integer;
j: Integer;
n: Integer;
json: TChilkatJsonObject;
mimeData: TChilkatBinData;
numSigs: Integer;

begin
success := 0;

// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.

imap := TChilkatImap.Create(Self);

// Connect to an IMAP server, login, select mailbox..
// Use TLS 
imap.Ssl := 1;
imap.Port := 993;
success := imap.Connect('imap.example.com');
if (success = 1) then
  begin
    success := imap.Login('myLogin','myPassword');
    if (success = 1) then
      begin
        success := imap.SelectMailbox('Inbox');
      end;
  end;
if (success <> 1) then
  begin
    Memo1.Lines.Add(imap.LastErrorText);
    Exit;
  end;

// Note: DKIM-Signatures are much more common than DomainKey-Signature
// See DKIM-Signature Verify Sample.

dkim := TChilkatDkim.Create(Self);

// Download a max of 10 emails and verify any DomainKey-Signature headers
// that are present.

// Download emails by sequence numbers (not UIDs).
bUid := 0;

n := imap.NumMessages;
if (n > 50) then
  begin
    n := 50;
  end;

json := TChilkatJsonObject.Create(Self);
json.EmitCompact := 0;

// To verify DomainKey-Signature headers, we need the exact unmodified MIME bytes of each email.
mimeData := TChilkatBinData.Create(Self);
seqNum := 1;
while seqNum <= n do
  begin
    // The FetchSingleBd method was introduced in v9.5.0.76
    success := imap.FetchSingleBd(seqNum,bUid,mimeData.ControlInterface);
    if (success <> 1) then
      begin
        Memo1.Lines.Add(imap.LastErrorText);
        Exit;
      end;

    // Note: DKIM-Signatures are much more common than DomainKey-Signature
    // See DKIM-Signature Verify Sample.

    // Get the number of DomainKey-Signature headers.
    numSigs := dkim.NumDomainKeySigs(mimeData.ControlInterface);

    // Verify each..
    j := 0;
    while j < numSigs do
      begin
        Memo1.Lines.Add('------ DomainKey Signature ' + IntToStr(j));

        success := dkim.DomainKeyVerify(j,mimeData.ControlInterface);
        if (success <> 1) then
          begin
            Memo1.Lines.Add('Not valid.');
            Memo1.Lines.Add(dkim.LastErrorText);
          end
        else
          begin
            Memo1.Lines.Add('valid.');
          end;

        // Show the additional information about the signature verification
        json.Load(dkim.VerifyInfo);
        Memo1.Lines.Add(json.Emit());

        // The JSON contains information such as this:

        // 	{
        // 	  "domain": "amazonses.com",
        // 	  "selector": "7v7vs6w47njt4pimodk5mmttbegzsi6n",
        // 	  "publicKey": "MIGfMA0GCSqG...v2GvWPqGHz6uqeQIDAQAB",
        // 	  "canonicalization": "relaxed/simple",
        // 	  "algorithm": "rsa-sha256",
        // 	  "signedHeaders": "Subject:From:To:Date:Mime-Version:Content-Type:References:Message-Id:Feedback-ID",
        // 	  "verified": "yes"
        // 	}

        j := j + 1;
      end;

    seqNum := seqNum + 1;
  end;

success := imap.Disconnect();
end;