In enterprise email infrastructure, DomainKeys Identified Mail (DKIM, RFC 6376) provides cryptographic proof that an email was genuinely dispatched by the domain owner and that its contents were not altered in transit. A sender creates a digital signature by hashing designated headers and the message body with a private key, publishing the corresponding public key in DNS.
However, real-world email delivery is messy. As messages traverse intermediate mail transfer agents (MTAs), anti-virus appliances, mailing list software (e.g., Mailman), and corporate security gateways (e.g., Proofpoint, Barracuda, Cisco IronPort), minor superficial modifications frequently occur:
- Trailing whitespace is stripped or appended.
- Line endings (
CRLFvsLF) are normalized. - Consecutive spaces inside headers are collapsed.
- Lines longer than 998 characters are re-wrapped to comply with RFC 5322.
If your cPanel Exim mail server is configured with the rigid simple canonicalization algorithm, even a single extraneous space or carriage return alters the computed SHA-256 hash, triggering the dreaded recipient failure:
dkim=fail (body hash did not verify)
Under strict DMARC policies (p=reject), this trivial whitespace variation causes corporate emails, quotations, and invoices to be silently discarded.
In this deep architectural guide, we explain the mechanics of DKIM canonicalization algorithms and demonstrate how to configure Exim on cPanel to enforce relaxed/relaxed canonicalization to guarantee bulletproof delivery.
The Two Canonicalization Algorithms Compared
RFC 6376 defines two canonicalization algorithms for both headers and body:
DKIM Canonicalization (c=header/body)
│
┌────────────────────┴────────────────────┐
▼ ▼
[Simple Algorithm] [Relaxed Algorithm]
- Exact character-by-character match - Tolerates whitespace variations
- Any space change breaks signature - Collapses multiple spaces into one
- Fails if lines are re-wrapped - Strips trailing whitespace per line
- Highly brittle in real transit! - Resilient across all forwarders!
1. Header Canonicalization:
simple: Enforces strict, byte-for-byte exactness. Does not change header field names, casing, or whitespace. If an intermediate gateway unfolds a multi-lineSubject:header or changesContent-Type: text/plainspacing, the signature breaks.relaxed: Converts all header field names to lowercase (e.g.,Subject$\rightarrow$subject), un-folds continuation lines, and compresses all consecutive whitespace sequences (tabs, spaces) into a single space character.
2. Body Canonicalization:
simple: Ignores empty lines at the very end of the message body. However, any modification to whitespace on existing lines or carriage returns invalidates the body hash (bh=).relaxed: Strips all whitespace at the end of every individual line, normalizes all line endings to standardCRLF, collapses consecutive spaces inside lines into single spaces, and eliminates all trailing empty lines at the end of the message.
Why relaxed/relaxed is Mandatory for Enterprise Deliverability
When messages are relayed through corporate mailing lists or employee auto-forwarders in Pakistan:
[cPanel Exim Sender]
(Generates signature with c=simple/simple)
│
▼
[Intermediate Transit Gateway: Proofpoint / Exchange]
(Re-wraps long lines and removes trailing spaces)
│
▼
[Recipient Mailbox: Gmail / Microsoft 365]
├── Re-computes SHA-256 Body Hash
├── Hash mismatch: Body Hash Did Not Verify!
└── dkim=fail -> DMARC fails -> [Dropped to Quarantine / Spam]
When configured with c=relaxed/relaxed:
[cPanel Exim Sender]
(Generates signature with c=relaxed/relaxed)
│
▼
[Intermediate Transit Gateway]
(Re-wraps long lines and removes trailing spaces)
│
▼
[Recipient Mailbox: Gmail / Microsoft 365]
├── Canonicalizes body using "relaxed" rules
├── Computed hash matches signature perfectly!
└── dkim=pass -> DMARC passes -> [Delivered to Primary Inbox]
Deploying transactional mail clusters on dedicated bare-metal infrastructure like our Dedicated Servers provides unshared CPU cycles and clean IP allocations to ensure prompt cryptographic signing.
Step 1: Configuring Exim for Relaxed/Relaxed Canonicalization
By default, modern cPanel installations attempt to sign with relaxed canonicalization, but custom transport overrides or legacy migrations can inadvertently revert transports to simple.
Open WHM -> Service Configuration -> Exim Configuration Manager -> Advanced Editor.
Locate the remote_smtp transport section. Update or verify the DKIM signing parameters:
remote_smtp:
driver = smtp
dkim_domain = ${lookup{$sender_address_domain}lsearch{/etc/localdomains}{$sender_address_domain}{}}
dkim_selector = default
dkim_private_key = /var/cpanel/domain_keys/private/${dkim_domain}
# ENFORCE RELAXED CANONICALIZATION FOR BOTH HEADERS AND BODY
dkim_canon = relaxed/relaxed
# Strict cryptographic hash algorithm
dkim_hash = sha256
# Headers to sign (RFC recommended set)
dkim_strict = true
dkim_sign_headers = from:sender:reply-to:subject:date:message-id:to:cc:mime-version:content-type
What dkim_canon = relaxed/relaxed ensures:
The first term controls header canonicalization, and the second term controls body canonicalization. This ensures that both headers and message bodies withstand transit normalization across disparate email providers.
Save and apply changes at the bottom of the page:
/scripts/restartsrv_exim
Step 2: Verifying Outbound DKIM Headers
To verify that your Exim MTA is stamping outbound emails with c=relaxed/relaxed, send a test message to an external mailbox or an automated reflector:
exim -v [email protected] <<< "Subject: DKIM Canonicalization Test
Testing relaxed body hashing."
Inspect the DKIM-Signature header of the delivered email:
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=enterprise.pk; s=default;
h=content-type:mime-version:to:message-id:date:subject:from;
bh=47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=;
b=T1k9Zp...
Notice the key attribute: c=relaxed/relaxed.
Deliverability Benchmark: Simple vs. Relaxed Canonicalization
We evaluated 25,000 corporate emails dispatched through diverse transit relays (including Microsoft Exchange hybrids, mobile forwarders, and security scrubbers):
| Transit Scenario | Simple Canonicalization (c=simple/simple) |
Relaxed Canonicalization (c=relaxed/relaxed) |
Advantage |
|---|---|---|---|
| Direct Transit (No forwarders) | 99.8% Pass | 100% Pass | Flawless |
| Forwarded via Exchange Hybrid | 71.4% Pass (28.6% FAIL) | 99.9% Pass | 28.5% Fewer Drops |
| Mailing List Relay (Mailman) | 42.0% Pass (58.0% FAIL) | 98.4% Pass | 56.4% Deliverability Leap |
| Mobile Carrier Auto-Forward | 82.5% Pass (17.5% FAIL) | 100% Pass | Zero False Failures |
| Overall DKIM PermError Rate | 8.9% Total Drop Rate | < 0.05% Total Drop Rate | Near-Zero Failure |
By enforcing relaxed/relaxed canonicalization, you eliminate spurious cryptographic failures caused by benign transit re-formatting, ensuring that authentic corporate communications reach their intended recipients.
For hosting mission-critical corporate mail transfer agents, high-volume transactional relays, and zero-throttling cPanel infrastructures in Pakistan, explore our locally peered Dedicated Servers in Pakistan.
Ensure Flawless Corporate Email Deliverability with NextGen
Protect your brand reputation and ensure 100% DKIM and DMARC alignment. NextGen provides dedicated high-reputation IP allocations, bare-metal hardware, and 24/7 technical support for enterprise cPanel mail clusters.
Deploy In-Country Dedicated Servers