DKIM record add / update

NethServer Version: 8
Module: mail, DKIM
Hi,
I still need to upgrade to NS8 (not looking forward to it, but have to).
Upon checking things, I see for some users I have a DNS/txt record with DKIM in place, however apparently I have not saved it in NS7. Therefore, these don’t have the OK checkmark.


What should be my approach:
A) migrate as is
B) add the DKIM check in NS7. I see this will renew the key, so I then need to update the existing DNS records. Only after this, migrate to NS8
C) first migrate, then add the DKIMcheck, and renewing DNS record.
D) B or C, doesn’t matter.

And more or less related: when updating this DKIM record, will there be a “blackout” period, where my server knows of the new key, but DNS is not propagated yet?

I’d recommend to migrate and setup the missing DKIM records from the NS8 so you don’t need to touch the NS7 and have a working fallback if something goes wrong during migration.

The already used DKIMs are migrated from NS7 to NS8 so it’s also possible to set it on the NS7 before migration.

The “blackout” period depends on what TTL is configured at your DNS provider.

2 Likes