Sample code for 30+ languages & platforms
.NET Core C#

Verify DomainKey-Signature Headers in Downloaded Email

See more DKIM / DomainKey Examples

Downloads email from an IMAP server and verifies the DomainKey-Signature header(s) in each email, if present.

Note: DKIM-Signatures are much more common than DomainKey-Signatures. See the other Chilkat example for verifying DKIM-Signatures (link in the code below).

Chilkat .NET Core C# Downloads

.NET Core C#
bool success = false;

// This example requires the Chilkat API to have been previously unlocked.
// See Global Unlock Sample for sample code.

Chilkat.Imap imap = new Chilkat.Imap();

// Connect to an IMAP server, login, select mailbox..
// Use TLS 
imap.Ssl = true;
imap.Port = 993;
success = imap.Connect("imap.example.com");
if (success == true) {
    success = imap.Login("myLogin","myPassword");
    if (success == true) {
        success = imap.SelectMailbox("Inbox");
    }

}

if (success != true) {
    Debug.WriteLine(imap.LastErrorText);
    return;
}

// Note: DKIM-Signatures are much more common than DomainKey-Signature
// See DKIM-Signature Verify Sample.

Chilkat.Dkim dkim = new Chilkat.Dkim();

// Download a max of 10 emails and verify any DomainKey-Signature headers
// that are present.

// Download emails by sequence numbers (not UIDs).
bool bUid = false;
int seqNum;
int j;
int n = imap.NumMessages;
if (n > 50) {
    n = 50;
}

Chilkat.JsonObject json = new Chilkat.JsonObject();
json.EmitCompact = false;

// To verify DomainKey-Signature headers, we need the exact unmodified MIME bytes of each email.
Chilkat.BinData mimeData = new Chilkat.BinData();
seqNum = 1;
while (seqNum <= n) {
    // The FetchSingleBd method was introduced in v9.5.0.76
    success = imap.FetchSingleBd(seqNum,bUid,mimeData);
    if (success != true) {
        Debug.WriteLine(imap.LastErrorText);
        return;
    }

    // Note: DKIM-Signatures are much more common than DomainKey-Signature
    // See DKIM-Signature Verify Sample.

    // Get the number of DomainKey-Signature headers.
    int numSigs = dkim.NumDomainKeySigs(mimeData);

    // Verify each..
    j = 0;
    while (j < numSigs) {
        Debug.WriteLine("------ DomainKey Signature " + Convert.ToString(j));

        success = dkim.DomainKeyVerify(j,mimeData);
        if (success != true) {
            Debug.WriteLine("Not valid.");
            Debug.WriteLine(dkim.LastErrorText);
        }
        else {
            Debug.WriteLine("valid.");
        }

        // Show the additional information about the signature verification
        json.Load(dkim.VerifyInfo);
        Debug.WriteLine(json.Emit());

        // The JSON contains information such as this:

        // 	{
        // 	  "domain": "amazonses.com",
        // 	  "selector": "7v7vs6w47njt4pimodk5mmttbegzsi6n",
        // 	  "publicKey": "MIGfMA0GCSqG...v2GvWPqGHz6uqeQIDAQAB",
        // 	  "canonicalization": "relaxed/simple",
        // 	  "algorithm": "rsa-sha256",
        // 	  "signedHeaders": "Subject:From:To:Date:Mime-Version:Content-Type:References:Message-Id:Feedback-ID",
        // 	  "verified": "yes"
        // 	}

        j = j + 1;
    }

    seqNum = seqNum + 1;
}

success = imap.Disconnect();