NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #3637 most downloaded on PyPI
DKIM (DomainKeys Identified Mail), ARC (Authenticated Receive Chain), and TLSRPT (TLS Report) email signing and verification
Last release 2 years ago
no release in 18 months
Ships unpredictably
gaps range from 2 weeks to 2.5 years
Most releases are documented
notes for 31 of 36 stable releases
Nothing withdrawn
no release was ever pulled
15 years old
36 releases · first in 2012
Correctly handle verification of signatures without t= (timestamp) and with x= (expiration); both are optional (LP: 2071892)
Fix error in validate_signature_fields which prevented signature expiration from being properly evaluated (LP: #2068937)
One column per quarter.
Use raw byte string for regex; fixes SyntaxWarning in Python 3.12 due to invalid escape sequence (LP: #2049518) - Thanks to Simon Chopin for the fix
Use dns.resolver.resolve instead of dns.resolver.query due to deprecation (LP: 2028783) - Thanks to Pedro Vicente for the report and the fix
Treat dns.resolver.NoNameservers like NXDOMAIN (not an error) (Thanks to David for the patch and the report)
Catch nacl.exceptions.ValueError and raise KeyFormatError, similar to how RSA key errors are treated (LP: #2018021)
Verify correct AMS header is used for ARC seal verification (André Cruz)
Document dropping of Python 2 support (dropped as of 1.1.0) (LP:
Add domain validity check for ascii domains (no specials)
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
dknewkey: On posix operating systems set file permissions to 600 for ed25519 private key files (as is already done for RSA) (LP: #1857827)
Follow CNAMES when looking up key records when using DNS (pydns) (LP: #1856421)
Add support for RFC 8460 tlsrpt DKIM signature processing (LP: #1847020)
Nothing published for this version
Ignore unknown service types in key records (LP: #1847020)
Add LICENSE to MANIFEST.in so it is included in the tarball (LP:
Fix linesep setting in arcsign script (LP: #1838262) (Thanks to Gowtham Gopalakrishnan for the report and the patch)
Fix the arcsign script so it works with the current API (Note: the new srv_id option is the authserv_id to use in the ARC signatures - Only AR fields
Fixed ARC verification to fail if h= tag is present in Arc-Seal and added tests
Update oversigned (frozen) header field list to reduce signature fragility (removes 'date' and 'subject' fields from being oversigned by default - see
Fix deprecation warnings in test asserts (Daniel Hahler)
Change from distutils to setuptools with entry points because it's the future
Update ed25519 tests, including using sample keys from RFC 8032 Section 7.1 and the sample message from RFC 6376
Initial ed25519 implementation based on draft-ietf-dcrup-dkim-crypto experimental - IETF draft, design not finalized, See README for details
Fixed problem with header folding that caused the first line to be folded too long (Updated test test_add_body_length since l= tag is no longer at the
- Fixed python3 dns lookup issue - Fixed arcverify.py issue
Add capability to sign and verify ARC signatures
Brown paper bag release, 0.5.5 tarball inadvertently included pyc files and other artifacts from development
Fix and test case for case insensitive subdomain matching.
Fixed error in FWS regular expression that cause some valid signatures to fail verification (Thanks to Peter Palfrader (weasel) for the patch) http://
Make key parsing error messages more specific to help troubleshooting based on user feedback
Change canonicalization defaults to work around issues with different verification implementations
Rename tarball to dkimpy to avoid confusion with original project
Your coding agent can read these notes before it upgrades. Set up the MCP server →