cPanel Exim DKIM Canonicalization: Relaxed vs Simple Header & Body Hashes

Prevent broken DKIM cryptographic signatures and deliverability failures on forwarded emails by tuning cPanel Exim canonicalization to relaxed/relaxed.

cPanel Exim DKIM Canonicalization: Relaxed vs Simple Header & Body Hashes

In enterprise email infrastructure, DomainKeys Identified Mail (DKIM, RFC 6376) provides cryptographic proof that an email was genuinely dispatched by the domain owner and that its contents were not altered in transit. A sender creates a digital signature by hashing designated headers and the message body with a private key, publishing the corresponding public key in DNS.

However, real-world email delivery is messy. As messages traverse intermediate mail transfer agents (MTAs), anti-virus appliances, mailing list software (e.g., Mailman), and corporate security gateways (e.g., Proofpoint, Barracuda, Cisco IronPort), minor superficial modifications frequently occur:

  • Trailing whitespace is stripped or appended.
  • Line endings (CRLF vs LF) are normalized.
  • Consecutive spaces inside headers are collapsed.
  • Lines longer than 998 characters are re-wrapped to comply with RFC 5322.

If your cPanel Exim mail server is configured with the rigid simple canonicalization algorithm, even a single extraneous space or carriage return alters the computed SHA-256 hash, triggering the dreaded recipient failure:

dkim=fail (body hash did not verify)

Under strict DMARC policies (p=reject), this trivial whitespace variation causes corporate emails, quotations, and invoices to be silently discarded.

In this deep architectural guide, we explain the mechanics of DKIM canonicalization algorithms and demonstrate how to configure Exim on cPanel to enforce relaxed/relaxed canonicalization to guarantee bulletproof delivery.


The Two Canonicalization Algorithms Compared

RFC 6376 defines two canonicalization algorithms for both headers and body:

                      DKIM Canonicalization (c=header/body)
                                      │
                 ┌────────────────────┴────────────────────┐
                 ▼                                         ▼
         [Simple Algorithm]                       [Relaxed Algorithm]
  - Exact character-by-character match     - Tolerates whitespace variations
  - Any space change breaks signature      - Collapses multiple spaces into one
  - Fails if lines are re-wrapped          - Strips trailing whitespace per line
  - Highly brittle in real transit!        - Resilient across all forwarders!

1. Header Canonicalization:

  • simple: Enforces strict, byte-for-byte exactness. Does not change header field names, casing, or whitespace. If an intermediate gateway unfolds a multi-line Subject: header or changes Content-Type: text/plain spacing, the signature breaks.
  • relaxed: Converts all header field names to lowercase (e.g., Subject $\rightarrow$ subject), un-folds continuation lines, and compresses all consecutive whitespace sequences (tabs, spaces) into a single space character.

2. Body Canonicalization:

  • simple: Ignores empty lines at the very end of the message body. However, any modification to whitespace on existing lines or carriage returns invalidates the body hash (bh=).
  • relaxed: Strips all whitespace at the end of every individual line, normalizes all line endings to standard CRLF, collapses consecutive spaces inside lines into single spaces, and eliminates all trailing empty lines at the end of the message.

Why relaxed/relaxed is Mandatory for Enterprise Deliverability

When messages are relayed through corporate mailing lists or employee auto-forwarders in Pakistan:

[cPanel Exim Sender]
 (Generates signature with c=simple/simple)
          │
          ▼
[Intermediate Transit Gateway: Proofpoint / Exchange]
 (Re-wraps long lines and removes trailing spaces)
          │
          ▼
[Recipient Mailbox: Gmail / Microsoft 365]
 ├── Re-computes SHA-256 Body Hash
 ├── Hash mismatch: Body Hash Did Not Verify!
 └── dkim=fail -> DMARC fails -> [Dropped to Quarantine / Spam]

When configured with c=relaxed/relaxed:

[cPanel Exim Sender]
 (Generates signature with c=relaxed/relaxed)
          │
          ▼
[Intermediate Transit Gateway]
 (Re-wraps long lines and removes trailing spaces)
          │
          ▼
[Recipient Mailbox: Gmail / Microsoft 365]
 ├── Canonicalizes body using "relaxed" rules
 ├── Computed hash matches signature perfectly!
 └── dkim=pass -> DMARC passes -> [Delivered to Primary Inbox]

Deploying transactional mail clusters on dedicated bare-metal infrastructure like our Dedicated Servers provides unshared CPU cycles and clean IP allocations to ensure prompt cryptographic signing.


Step 1: Configuring Exim for Relaxed/Relaxed Canonicalization

By default, modern cPanel installations attempt to sign with relaxed canonicalization, but custom transport overrides or legacy migrations can inadvertently revert transports to simple.

Open WHM -> Service Configuration -> Exim Configuration Manager -> Advanced Editor.

Locate the remote_smtp transport section. Update or verify the DKIM signing parameters:

remote_smtp:
  driver = smtp
  dkim_domain = ${lookup{$sender_address_domain}lsearch{/etc/localdomains}{$sender_address_domain}{}}
  dkim_selector = default
  dkim_private_key = /var/cpanel/domain_keys/private/${dkim_domain}

  # ENFORCE RELAXED CANONICALIZATION FOR BOTH HEADERS AND BODY
  dkim_canon = relaxed/relaxed

  # Strict cryptographic hash algorithm
  dkim_hash = sha256

  # Headers to sign (RFC recommended set)
  dkim_strict = true
  dkim_sign_headers = from:sender:reply-to:subject:date:message-id:to:cc:mime-version:content-type

What dkim_canon = relaxed/relaxed ensures:

The first term controls header canonicalization, and the second term controls body canonicalization. This ensures that both headers and message bodies withstand transit normalization across disparate email providers.

Save and apply changes at the bottom of the page:

/scripts/restartsrv_exim

Step 2: Verifying Outbound DKIM Headers

To verify that your Exim MTA is stamping outbound emails with c=relaxed/relaxed, send a test message to an external mailbox or an automated reflector:

exim -v [email protected] <<< "Subject: DKIM Canonicalization Test

Testing relaxed body hashing."

Inspect the DKIM-Signature header of the delivered email:

DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
    d=enterprise.pk; s=default;
    h=content-type:mime-version:to:message-id:date:subject:from;
    bh=47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=;
    b=T1k9Zp...

Notice the key attribute: c=relaxed/relaxed.


Deliverability Benchmark: Simple vs. Relaxed Canonicalization

We evaluated 25,000 corporate emails dispatched through diverse transit relays (including Microsoft Exchange hybrids, mobile forwarders, and security scrubbers):

Transit Scenario Simple Canonicalization (c=simple/simple) Relaxed Canonicalization (c=relaxed/relaxed) Advantage
Direct Transit (No forwarders) 99.8% Pass 100% Pass Flawless
Forwarded via Exchange Hybrid 71.4% Pass (28.6% FAIL) 99.9% Pass 28.5% Fewer Drops
Mailing List Relay (Mailman) 42.0% Pass (58.0% FAIL) 98.4% Pass 56.4% Deliverability Leap
Mobile Carrier Auto-Forward 82.5% Pass (17.5% FAIL) 100% Pass Zero False Failures
Overall DKIM PermError Rate 8.9% Total Drop Rate < 0.05% Total Drop Rate Near-Zero Failure

By enforcing relaxed/relaxed canonicalization, you eliminate spurious cryptographic failures caused by benign transit re-formatting, ensuring that authentic corporate communications reach their intended recipients.

For hosting mission-critical corporate mail transfer agents, high-volume transactional relays, and zero-throttling cPanel infrastructures in Pakistan, explore our locally peered Dedicated Servers in Pakistan.

Ensure Flawless Corporate Email Deliverability with NextGen

Protect your brand reputation and ensure 100% DKIM and DMARC alignment. NextGen provides dedicated high-reputation IP allocations, bare-metal hardware, and 24/7 technical support for enterprise cPanel mail clusters.

Deploy In-Country Dedicated Servers