@lacspace/dkim
DKIM signing and verification for email: RFC 6376 (rsa-sha256, simple/relaxed canonicalization, l=, x=, t=, oversigned From), RFC 8463 Ed25519 (ed25519-sha256) and RFC 8301 (rsa-sha1 and keys under 1024 bits rejected). signMessage(), verifyMessage() with multiple signatures, From alignment, revoked/missing keys and injectable DNS. Key generation and ready-to-paste DNS TXT records split into 255-character strings. Pure WebCrypto, zero dependencies, isomorphic.
npm i @lacspace/dkimUsage
import { signMessage, verifyMessage, generateKeyPair } from "@lacspace/dkim";
const signed = await signMessage(rawMime, {
domain: "example.com",
selector: "mail2026",
privateKey: process.env.DKIM_PRIVATE_KEY!, // PKCS#8 PEM
});
// "DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=example.com; s=mail2026; t=…;\r\n h=from:to:subject:date:message-id:from; bh=…; b=…\r\n" + rawMime
const { pass, results } = await verifyMessage(incomingRaw);
// pass: true when at least one signature verifies AND its d= aligns with the From domain
// results: [{ domain: "example.com", selector: "mail2026", algorithm: "rsa-sha256", status: "pass",
// aligned: true, canonicalization: "relaxed/relaxed", signedHeaders: [...], bodyHashOk: true, keyBits: 2048 }]Exports 18
DEFAULT_SIGNED_HEADERSDkimErrorcanonicalizeBodycanonicalizeHeaderchunkTxtdkimDnsRecorded25519SeedToPkcs8fromDomainOfgenerateKeyPairimportPrivateKeyparseDkimKeyparseDkimSignatureparseTagListsignHeadersignMessagestripSignatureValuetoPemverifyMessageKeywords
More in Mail Kit
Compose bulletproof, responsive, dark-mode HTML emails from simple blocks, plus 13 ready-made transactional templates (OTP, verify, password-reset, magic-link, receipt, order, shipping, invitation, digest, announcement). Ships plaintext generation, preheaders and {{var}} i18n interpolation. Zero-dependency, isomorphic.
@lacspace/email-validateSmart, network-free email validation — RFC-5322 syntax (incl. quoted local parts & IP-literal domains), disposable/temp-mail & role-account detection, free-provider flags, Gmail normalization and 'did you mean?' typo suggestions. Zero-dependency, isomorphic.
@lacspace/email-verifyBest-effort email deliverability for Node — syntax + disposable/role, MX lookup with priority ranking, an optional SMTP RCPT probe (no mail sent), catch-all detection, a 0-100 confidence score, and de-duped batch verification. All DNS/SMTP injectable; zero npm dependencies.
@lacspace/mailerA tiny zero-dependency SMTP client for Node — send email over raw net/tls with STARTTLS & AUTH, plus a fluent MIME builder (inline images, attachments, alternatives), RFC 5322 address + RFC 2047 helpers, batch send with retry, and no-network test transports. Provider presets (Hostinger, Gmail, Outlook, Zoho…) make setup one line.
@lacspace/imapZero-dependency IMAP4rev1 client for Node (RFC 3501 + IDLE, MOVE, UIDPLUS, CONDSTORE, SPECIAL-USE, LIST-EXTENDED, LITERAL+, SASL-IR, QUOTA, ID). Implicit TLS and STARTTLS with verification on, LOGIN / PLAIN / XOAUTH2 / OAUTHBEARER, streaming byte-accurate parser, async-iterable FETCH, envelopes with RFC 2047 decoding, BODYSTRUCTURE trees shared with @lacspace/mime, modified UTF-7 mailbox names, special-use detection (incl. Gmail XLIST and localised names), IDLE with NOOP fallback. Works with Hostinger (Dovecot), Gmail, Outlook/Exchange, GoDaddy.
@lacspace/mimeIsomorphic RFC 5322 / RFC 2045-2049 MIME parser and builder for webmail. parseMime() turns raw mail (string or bytes) into from/to/cc/subject/date/text/html/attachments/inline cid images/priority/List-Unsubscribe one-click and the part tree; handles nested multipart (mixed, alternative, related, report, signed), message/rfc822 forwards, base64 and quoted-printable (tolerant), RFC 2047 encoded words (split multibyte, adjacent whitespace), RFC 2231 parameters, 30+ charsets and malformed input without ever throwing. parseBodyStructure() parses IMAP BODYSTRUCTURE (literals, extension data) into the same tree with IMAP partIds, plus findTextParts / listAttachments / decodePart for lazy fetching. buildMime() writes CRLF messages with encoded-word headers, QP/base64 bodies, mixed/alternative/related nesting, Message-ID generation and header-injection guards; replyHeaders() / forwardSubject() for threading. Pairs with @lacspace/imap and @lacspace/mailer. Zero dependencies; Node 18+, edge runtimes and browsers.