Skip to main content

mail_auth/dkim/
parse.rs

1/*
2 * SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <hello@stalw.art>
3 *
4 * SPDX-License-Identifier: Apache-2.0 OR MIT
5 */
6
7use super::{
8    Algorithm, Atps, Canonicalization, DomainKeyReport, Flag, HashAlgorithm, RR_DNS, RR_OTHER,
9    RR_POLICY, Service, Signature, Version,
10};
11use crate::{
12    Error,
13    common::{crypto::VerifyingKeyType, parse::*, verify::DomainKey},
14    dkim::{RR_EXPIRATION, RR_SIGNATURE, RR_UNKNOWN_TAG, RR_VERIFICATION},
15};
16use mail_parser::decoders::base64::base64_decode_stream;
17use std::slice::Iter;
18
19const ATPSH: u64 = (b'a' as u64)
20    | ((b't' as u64) << 8)
21    | ((b'p' as u64) << 16)
22    | ((b's' as u64) << 24)
23    | ((b'h' as u64) << 32);
24const ATPS: u64 =
25    (b'a' as u64) | ((b't' as u64) << 8) | ((b'p' as u64) << 16) | ((b's' as u64) << 24);
26const NONE: u64 =
27    (b'n' as u64) | ((b'o' as u64) << 8) | ((b'n' as u64) << 16) | ((b'e' as u64) << 24);
28const SHA256: u64 = (b's' as u64)
29    | ((b'h' as u64) << 8)
30    | ((b'a' as u64) << 16)
31    | ((b'2' as u64) << 24)
32    | ((b'5' as u64) << 32)
33    | ((b'6' as u64) << 40);
34const SHA1: u64 =
35    (b's' as u64) | ((b'h' as u64) << 8) | ((b'a' as u64) << 16) | ((b'1' as u64) << 24);
36const RA: u64 = (b'r' as u64) | ((b'a' as u64) << 8);
37const RP: u64 = (b'r' as u64) | ((b'p' as u64) << 8);
38const RR: u64 = (b'r' as u64) | ((b'r' as u64) << 8);
39const RS: u64 = (b'r' as u64) | ((b's' as u64) << 8);
40const ALL: u64 = (b'a' as u64) | ((b'l' as u64) << 8) | ((b'l' as u64) << 16);
41
42impl Signature {
43    #[allow(clippy::while_let_on_iterator)]
44    pub fn parse(header: &'_ [u8]) -> crate::Result<Self> {
45        let mut signature = Signature {
46            v: 0,
47            a: Algorithm::RsaSha256,
48            d: "".into(),
49            s: "".into(),
50            i: "".into(),
51            b: Vec::with_capacity(0),
52            bh: Vec::with_capacity(0),
53            h: Vec::with_capacity(0),
54            z: Vec::with_capacity(0),
55            l: 0,
56            x: 0,
57            t: 0,
58            ch: Canonicalization::Simple,
59            cb: Canonicalization::Simple,
60            r: false,
61            atps: None,
62            atpsh: None,
63        };
64        let header_len = header.len();
65        let mut header = header.iter();
66
67        while let Some(key) = header.key() {
68            match key {
69                V => {
70                    signature.v = header.number().unwrap_or(0) as u32;
71                    if signature.v != 1 {
72                        return Err(Error::UnsupportedVersion);
73                    }
74                }
75                A => {
76                    signature.a = header.algorithm()?;
77                }
78                B => {
79                    signature.b =
80                        base64_decode_stream(&mut header, header_len, b';').ok_or(Error::Base64)?
81                }
82                BH => {
83                    signature.bh =
84                        base64_decode_stream(&mut header, header_len, b';').ok_or(Error::Base64)?
85                }
86                C => {
87                    let (ch, cb) = header.canonicalization(Canonicalization::Simple)?;
88                    signature.ch = ch;
89                    signature.cb = cb;
90                }
91                D => signature.d = header.text(true),
92                H => signature.h = header.items(),
93                I => signature.i = header.text_qp(Vec::with_capacity(20), true, false),
94                L => signature.l = header.number().unwrap_or(0),
95                S => signature.s = header.text(true),
96                T => signature.t = header.number().unwrap_or(0),
97                X => signature.x = header.number().unwrap_or(0),
98                Z => signature.z = header.headers_qp(),
99                R => signature.r = header.value() == Y,
100                ATPS => {
101                    if signature.atps.is_none() {
102                        signature.atps = Some(header.text(true));
103                    }
104                }
105                ATPSH => {
106                    signature.atpsh = match header.value() {
107                        SHA256 => HashAlgorithm::Sha256.into(),
108                        SHA1 => HashAlgorithm::Sha1.into(),
109                        NONE => None,
110                        _ => {
111                            signature.atps = Some("".into());
112                            None
113                        }
114                    };
115                }
116                _ => header.ignore(),
117            }
118        }
119
120        if !signature.d.is_empty()
121            && !signature.s.is_empty()
122            && !signature.b.is_empty()
123            && !signature.bh.is_empty()
124            && !signature.h.is_empty()
125        {
126            Ok(signature)
127        } else {
128            Err(Error::MissingParameters)
129        }
130    }
131}
132
133pub(crate) trait SignatureParser: Sized {
134    fn canonicalization(
135        &mut self,
136        default: Canonicalization,
137    ) -> crate::Result<(Canonicalization, Canonicalization)>;
138    fn algorithm(&mut self) -> crate::Result<Algorithm>;
139}
140
141impl SignatureParser for Iter<'_, u8> {
142    fn canonicalization(
143        &mut self,
144        default: Canonicalization,
145    ) -> crate::Result<(Canonicalization, Canonicalization)> {
146        let mut cb = default;
147        let mut ch = default;
148
149        let mut has_header = false;
150        let mut c = None;
151
152        while let Some(char) = self.next() {
153            match (char, c) {
154                (b's' | b'S', None) => {
155                    if self.match_bytes(b"imple") {
156                        c = Canonicalization::Simple.into();
157                    } else {
158                        return Err(Error::UnsupportedCanonicalization);
159                    }
160                }
161                (b'r' | b'R', None) => {
162                    if self.match_bytes(b"elaxed") {
163                        c = Canonicalization::Relaxed.into();
164                    } else {
165                        return Err(Error::UnsupportedCanonicalization);
166                    }
167                }
168                (b'/', Some(c_)) => {
169                    ch = c_;
170                    c = None;
171                    has_header = true;
172                }
173                (b';', _) => {
174                    break;
175                }
176                (_, _) => {
177                    if !char.is_ascii_whitespace() {
178                        return Err(Error::UnsupportedCanonicalization);
179                    }
180                }
181            }
182        }
183
184        if let Some(c) = c {
185            if has_header {
186                cb = c;
187            } else {
188                ch = c;
189            }
190        }
191
192        Ok((ch, cb))
193    }
194
195    fn algorithm(&mut self) -> crate::Result<Algorithm> {
196        match self.next_skip_whitespaces().unwrap_or(0) {
197            b'r' | b'R' => {
198                if self.match_bytes(b"sa-sha") {
199                    let mut algo = 0;
200
201                    for ch in self {
202                        match ch {
203                            b'1' if algo == 0 => algo = 1,
204                            b'2' if algo == 0 => algo = 2,
205                            b'5' if algo == 2 => algo = 25,
206                            b'6' if algo == 25 => algo = 256,
207                            b';' => {
208                                break;
209                            }
210                            _ => {
211                                if !ch.is_ascii_whitespace() {
212                                    return Err(Error::UnsupportedAlgorithm);
213                                }
214                            }
215                        }
216                    }
217
218                    match algo {
219                        256 => Ok(Algorithm::RsaSha256),
220                        1 => Ok(Algorithm::RsaSha1),
221                        _ => Err(Error::UnsupportedAlgorithm),
222                    }
223                } else {
224                    Err(Error::UnsupportedAlgorithm)
225                }
226            }
227            b'e' | b'E' => {
228                if self.match_bytes(b"d25519-sha256") && self.seek_tag_end() {
229                    Ok(Algorithm::Ed25519Sha256)
230                } else {
231                    Err(Error::UnsupportedAlgorithm)
232                }
233            }
234            _ => Err(Error::UnsupportedAlgorithm),
235        }
236    }
237}
238
239impl TxtRecordParser for DomainKey {
240    #[allow(clippy::while_let_on_iterator)]
241    fn parse(header: &[u8]) -> crate::Result<Self> {
242        let header_len = header.len();
243        let mut header = header.iter();
244        let mut flags = 0;
245        let mut key_type = VerifyingKeyType::Rsa;
246        let mut public_key = None;
247
248        while let Some(key) = header.key() {
249            match key {
250                V => {
251                    if !header.match_bytes(b"DKIM1") || !header.seek_tag_end() {
252                        return Err(Error::InvalidRecordType);
253                    }
254                }
255                H => flags |= header.flags::<HashAlgorithm>(),
256                P => {
257                    if let Some(bytes) = base64_decode_stream(&mut header, header_len, b';') {
258                        public_key = Some(bytes);
259                    }
260                }
261                S => flags |= header.flags::<Service>(),
262                T => flags |= header.flags::<Flag>(),
263                K => {
264                    if let Some(ch) = header.next_skip_whitespaces() {
265                        match ch {
266                            b'r' | b'R' if header.match_bytes(b"sa") && header.seek_tag_end() => {
267                                key_type = VerifyingKeyType::Rsa;
268                            }
269                            b'e' | b'E'
270                                if header.match_bytes(b"d25519") && header.seek_tag_end() =>
271                            {
272                                key_type = VerifyingKeyType::Ed25519;
273                            }
274                            b';' => (),
275                            _ => {
276                                return Err(Error::UnsupportedKeyType);
277                            }
278                        }
279                    }
280                }
281                _ => {
282                    header.ignore();
283                }
284            }
285        }
286
287        match public_key {
288            Some(public_key) => Ok(DomainKey {
289                p: key_type.verifying_key(&public_key)?,
290                f: flags,
291            }),
292            _ => Err(Error::InvalidRecordType),
293        }
294    }
295}
296
297impl TxtRecordParser for DomainKeyReport {
298    #[allow(clippy::while_let_on_iterator)]
299    fn parse(header: &[u8]) -> crate::Result<Self> {
300        let mut header = header.iter();
301        let mut record = DomainKeyReport {
302            ra: String::new(),
303            rp: 100,
304            rr: u8::MAX,
305            rs: None,
306        };
307
308        while let Some(key) = header.key() {
309            match key {
310                RA => {
311                    record.ra = header.text_qp(Vec::with_capacity(20), true, false);
312                }
313                RP => {
314                    record.rp = std::cmp::min(header.number().unwrap_or(0), 100) as u8;
315                }
316                RS => {
317                    record.rs = header.text_qp(Vec::with_capacity(20), false, false).into();
318                }
319                RR => {
320                    record.rr = 0;
321                    loop {
322                        let (val, stop_char) = header.flag_value();
323                        match val {
324                            ALL => {
325                                record.rr = u8::MAX;
326                            }
327                            D => {
328                                record.rr |= RR_DNS;
329                            }
330                            O => {
331                                record.rr |= RR_OTHER;
332                            }
333                            P => {
334                                record.rr |= RR_POLICY;
335                            }
336                            S => {
337                                record.rr |= RR_SIGNATURE;
338                            }
339                            U => {
340                                record.rr |= RR_UNKNOWN_TAG;
341                            }
342                            V => {
343                                record.rr |= RR_VERIFICATION;
344                            }
345                            X => {
346                                record.rr |= RR_EXPIRATION;
347                            }
348                            _ => (),
349                        }
350
351                        if stop_char != b':' {
352                            break;
353                        }
354                    }
355                }
356
357                _ => {
358                    header.ignore();
359                }
360            }
361        }
362
363        if !record.ra.is_empty() {
364            Ok(record)
365        } else {
366            Err(Error::InvalidRecordType)
367        }
368    }
369}
370
371impl TxtRecordParser for Atps {
372    #[allow(clippy::while_let_on_iterator)]
373    fn parse(header: &[u8]) -> crate::Result<Self> {
374        let mut header = header.iter();
375        let mut record = Atps {
376            v: Version::V1,
377            d: None,
378        };
379        let mut has_version = false;
380
381        while let Some(key) = header.key() {
382            match key {
383                V => {
384                    if !header.match_bytes(b"ATPS1") || !header.seek_tag_end() {
385                        return Err(Error::InvalidRecordType);
386                    }
387                    has_version = true;
388                }
389                D => {
390                    record.d = header.text(true).into();
391                }
392                _ => {
393                    header.ignore();
394                }
395            }
396        }
397
398        if !has_version {
399            return Err(Error::InvalidRecordType);
400        }
401
402        Ok(record)
403    }
404}
405
406impl DomainKey {
407    pub fn has_flag(&self, flag: impl Into<u64>) -> bool {
408        (self.f & flag.into()) != 0
409    }
410}
411
412impl ItemParser for HashAlgorithm {
413    fn parse(bytes: &[u8]) -> Option<Self> {
414        if bytes.eq_ignore_ascii_case(b"sha256") {
415            HashAlgorithm::Sha256.into()
416        } else if bytes.eq_ignore_ascii_case(b"sha1") {
417            HashAlgorithm::Sha1.into()
418        } else {
419            None
420        }
421    }
422}
423
424impl ItemParser for Flag {
425    fn parse(bytes: &[u8]) -> Option<Self> {
426        if bytes.eq_ignore_ascii_case(b"y") {
427            Flag::Testing.into()
428        } else if bytes.eq_ignore_ascii_case(b"s") {
429            Flag::MatchDomain.into()
430        } else {
431            None
432        }
433    }
434}
435
436impl ItemParser for Service {
437    fn parse(bytes: &[u8]) -> Option<Self> {
438        if bytes.eq(b"*") {
439            Service::All.into()
440        } else if bytes.eq_ignore_ascii_case(b"email") {
441            Service::Email.into()
442        } else {
443            None
444        }
445    }
446}
447
448#[cfg(test)]
449mod test {
450    use mail_parser::decoders::base64::base64_decode;
451
452    use crate::{
453        common::{
454            crypto::{Algorithm, R_HASH_SHA1, R_HASH_SHA256},
455            parse::TxtRecordParser,
456            verify::DomainKey,
457        },
458        dkim::{
459            Canonicalization, DomainKeyReport, R_FLAG_MATCH_DOMAIN, R_FLAG_TESTING, R_SVC_ALL,
460            R_SVC_EMAIL, RR_DNS, RR_EXPIRATION, RR_OTHER, RR_POLICY, RR_SIGNATURE, RR_UNKNOWN_TAG,
461            RR_VERIFICATION, Signature,
462        },
463    };
464
465    #[test]
466    fn dkim_signature_parse() {
467        for (signature, expected_result) in [
468            (
469                concat!(
470                    "v=1; a=rsa-sha256; s=default; d=stalw.art; c=relaxed/relaxed; ",
471                    "bh=QoiUNYyUV+1tZ/xUPRcE+gST2zAStvJx1OK078Ylm5s=; ",
472                    "b=Du0rvdzNodI6b5bhlUaZZ+gpXJi0VwjY/3qL7lS0wzKutNVCbvdJuZObGdAcv\n",
473                    " eVI/RNQh2gxW4H2ynMS3B+Unse1YLJQwdjuGxsCEKBqReKlsEKT8JlO/7b2AvxR\n",
474                    "\t9Q+M2aHD5kn9dbNIKnN/PKouutaXmm18QwL5EPEN9DHXSqQ=;",
475                    "h=Subject:To:From; t=311923920",
476                ),
477                Signature {
478                    v: 1,
479                    a: Algorithm::RsaSha256,
480                    d: "stalw.art".into(),
481                    s: "default".into(),
482                    i: "".into(),
483                    bh: base64_decode(b"QoiUNYyUV+1tZ/xUPRcE+gST2zAStvJx1OK078Ylm5s=").unwrap(),
484                    b: base64_decode(
485                        concat!(
486                            "Du0rvdzNodI6b5bhlUaZZ+gpXJi0VwjY/3qL7lS0wzKutNVCbvdJuZObGdAcv",
487                            "eVI/RNQh2gxW4H2ynMS3B+Unse1YLJQwdjuGxsCEKBqReKlsEKT8JlO/7b2AvxR",
488                            "9Q+M2aHD5kn9dbNIKnN/PKouutaXmm18QwL5EPEN9DHXSqQ="
489                        )
490                        .as_bytes(),
491                    )
492                    .unwrap(),
493                    h: vec!["Subject".into(), "To".into(), "From".into()],
494                    z: vec![],
495                    l: 0,
496                    x: 0,
497                    t: 311923920,
498                    ch: Canonicalization::Relaxed,
499                    cb: Canonicalization::Relaxed,
500                    r: false,
501                    atps: None,
502                    atpsh: None,
503                },
504            ),
505            (
506                concat!(
507                    "v=1; a=rsa-sha1; d=example.net; s=brisbane;\r\n",
508                    " c=simple; q=dns/txt; i=@eng.example.net;\r\n",
509                    " t=1117574938; x=1118006938;\r\n",
510                    " h=from:to:subject:date;\r\n",
511                    " z=From:foo@eng.example.net|To:joe@example.com|\r\n",
512                    " Subject:demo=20run|Date:July=205,=202005=203:44:08=20PM=20-0700;\r\n",
513                    " bh=MTIzNDU2Nzg5MDEyMzQ1Njc4OTAxMjM0NTY3ODkwMTI=;\r\n",
514                    " b=dzdVyOfAKCdLXdJOc9G2q8LoXSlEniSbav+yuU4zGeeruD00lszZVoG4ZHRNiYzR",
515                ),
516                Signature {
517                    v: 1,
518                    a: Algorithm::RsaSha1,
519                    d: "example.net".into(),
520                    s: "brisbane".into(),
521                    i: "@eng.example.net".into(),
522                    bh: base64_decode(b"MTIzNDU2Nzg5MDEyMzQ1Njc4OTAxMjM0NTY3ODkwMTI=").unwrap(),
523                    b: base64_decode(
524                        concat!(
525                            "dzdVyOfAKCdLXdJOc9G2q8LoXSlEniSbav+yuU4zGe",
526                            "eruD00lszZVoG4ZHRNiYzR"
527                        )
528                        .as_bytes(),
529                    )
530                    .unwrap(),
531                    h: vec!["from".into(), "to".into(), "subject".into(), "date".into()],
532                    z: vec![
533                        "From:foo@eng.example.net".into(),
534                        "To:joe@example.com".into(),
535                        "Subject:demo run".into(),
536                        "Date:July 5, 2005 3:44:08 PM -0700".into(),
537                    ],
538                    l: 0,
539                    x: 1118006938,
540                    t: 1117574938,
541                    ch: Canonicalization::Simple,
542                    cb: Canonicalization::Simple,
543                    r: false,
544                    atps: None,
545                    atpsh: None,
546                },
547            ),
548            (
549                concat!(
550                    "v=1; a = rsa - sha256; s = brisbane; d = example.com;  \r\n",
551                    "c = simple / relaxed; q=dns/txt; i = \r\n joe=20@\r\n",
552                    " football.example.com; \r\n",
553                    "h=Received : From : To :\r\n Subject : : Date : Message-ID::;;;; \r\n",
554                    "bh=2jUSOH9NhtVGCQWNr9BrIAPreKQjO6Sn7XIkfJVOzv8=; \r\n",
555                    "b=AuUoFEfDxTDkHlLXSZEpZj79LICEps6eda7W3deTVFOk4yAUoqOB \r\n",
556                    "4nujc7YopdG5dWLSdNg6xNAZpOPr+kHxt1IrE+NahM6L/LbvaHut \r\n",
557                    "KVdkLLkpVaVVQPzeRDI009SO2Il5Lu7rDNH6mZckBdrIx0orEtZV \r\n",
558                    "4bmp/YzhwvcubU4=; l = 123",
559                ),
560                Signature {
561                    v: 1,
562                    a: Algorithm::RsaSha256,
563                    d: "example.com".into(),
564                    s: "brisbane".into(),
565                    i: "joe @football.example.com".into(),
566                    bh: base64_decode(b"2jUSOH9NhtVGCQWNr9BrIAPreKQjO6Sn7XIkfJVOzv8=").unwrap(),
567                    b: base64_decode(
568                        concat!(
569                            "AuUoFEfDxTDkHlLXSZEpZj79LICEps6eda7W3deTVFOk4yAUoqOB",
570                            "4nujc7YopdG5dWLSdNg6xNAZpOPr+kHxt1IrE+NahM6L/LbvaHut",
571                            "KVdkLLkpVaVVQPzeRDI009SO2Il5Lu7rDNH6mZckBdrIx0orEtZV",
572                            "4bmp/YzhwvcubU4="
573                        )
574                        .as_bytes(),
575                    )
576                    .unwrap(),
577                    h: vec![
578                        "Received".into(),
579                        "From".into(),
580                        "To".into(),
581                        "Subject".into(),
582                        "Date".into(),
583                        "Message-ID".into(),
584                    ],
585                    z: vec![],
586                    l: 123,
587                    x: 0,
588                    t: 0,
589                    ch: Canonicalization::Simple,
590                    cb: Canonicalization::Relaxed,
591                    r: false,
592                    atps: None,
593                    atpsh: None,
594                },
595            ),
596        ] {
597            let result = Signature::parse(signature.as_bytes()).unwrap();
598            assert_eq!(result.v, expected_result.v, "{signature:?}");
599            assert_eq!(result.a, expected_result.a, "{signature:?}");
600            assert_eq!(result.d, expected_result.d, "{signature:?}");
601            assert_eq!(result.s, expected_result.s, "{signature:?}");
602            assert_eq!(result.i, expected_result.i, "{signature:?}");
603            assert_eq!(result.b, expected_result.b, "{signature:?}");
604            assert_eq!(result.bh, expected_result.bh, "{signature:?}");
605            assert_eq!(result.h, expected_result.h, "{signature:?}");
606            assert_eq!(result.z, expected_result.z, "{signature:?}");
607            assert_eq!(result.l, expected_result.l, "{signature:?}");
608            assert_eq!(result.x, expected_result.x, "{signature:?}");
609            assert_eq!(result.t, expected_result.t, "{signature:?}");
610            assert_eq!(result.ch, expected_result.ch, "{signature:?}");
611            assert_eq!(result.cb, expected_result.cb, "{signature:?}");
612        }
613    }
614
615    #[test]
616    fn dkim_record_parse() {
617        for (record, expected_result) in [
618            (
619                concat!(
620                    "v=DKIM1; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQ",
621                    "KBgQDwIRP/UC3SBsEmGqZ9ZJW3/DkMoGeLnQg1fWn7/zYt",
622                    "IxN2SnFCjxOCKG9v3b4jYfcTNh5ijSsq631uBItLa7od+v",
623                    "/RtdC2UzJ1lWT947qR+Rcac2gbto/NMqJ0fzfVjH4OuKhi",
624                    "tdY9tf6mcwGjaNBcWToIMmPSPDdQPNUYckcQ2QIDAQAB",
625                ),
626                0,
627            ),
628            (
629                concat!(
630                    "v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOC",
631                    "AQ8AMIIBCgKCAQEAvzwKQIIWzQXv0nihasFTT3+JO23hXCg",
632                    "e+ESWNxCJdVLxKL5edxrumEU3DnrPeGD6q6E/vjoXwBabpm",
633                    "8F5o96MEPm7v12O5IIK7wx7gIJiQWvexwh+GJvW4aFFa0g1",
634                    "3Ai75UdZjGFNKHAEGeLmkQYybK/EHW5ymRlSg3g8zydJGEc",
635                    "I/melLCiBoShHjfZFJEThxLmPHNSi+KOUMypxqYHd7hzg6W",
636                    "7qnq6t9puZYXMWj6tEaf6ORWgb7DOXZSTJJjAJPBWa2+Urx",
637                    "XX6Ro7L7Xy1zzeYFCk8W5vmn0wMgGpjkWw0ljJWNwIpxZAj9",
638                    "p5wMedWasaPS74TZ1b7tI39ncp6QIDAQAB ; t= y : s :yy:x;",
639                    "s=*:email;; h= sha1:sha 256:other;; n=ignore these notes "
640                ),
641                R_HASH_SHA1
642                    | R_HASH_SHA256
643                    | R_SVC_ALL
644                    | R_SVC_EMAIL
645                    | R_FLAG_MATCH_DOMAIN
646                    | R_FLAG_TESTING,
647            ),
648            (
649                concat!(
650                    "p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCYtb/9Sh8nGKV7exhUFS",
651                    "+cBNXlHgO1CxD9zIfQd5ztlq1LO7g38dfmFpQafh9lKgqPBTolFhZxhF1yUNT",
652                    "hpV673NdAtaCVGNyx/fTYtvyyFe9DH2tmm/ijLlygDRboSkIJ4NHZjK++48hk",
653                    "NP8/htqWHS+CvwWT4Qgs0NtB7Re9bQIDAQAB"
654                ),
655                0,
656            ),
657        ] {
658            assert_eq!(
659                DomainKey::parse(record.as_bytes()).unwrap().f,
660                expected_result
661            );
662        }
663    }
664
665    #[test]
666    fn dkim_report_record_parse() {
667        for (record, expected_result) in [
668            (
669                "ra=dkim-errors; rp=97; rr=v:x",
670                DomainKeyReport {
671                    ra: "dkim-errors".to_string(),
672                    rp: 97,
673                    rr: RR_VERIFICATION | RR_EXPIRATION,
674                    rs: None,
675                },
676            ),
677            (
678                "ra=postmaster; rp=1; rr=d:o:p:s:u:v:x; rs=Error=20Message;",
679                DomainKeyReport {
680                    ra: "postmaster".to_string(),
681                    rp: 1,
682                    rr: RR_DNS
683                        | RR_OTHER
684                        | RR_POLICY
685                        | RR_SIGNATURE
686                        | RR_UNKNOWN_TAG
687                        | RR_VERIFICATION
688                        | RR_EXPIRATION,
689                    rs: "Error Message".to_string().into(),
690                },
691            ),
692        ] {
693            assert_eq!(
694                DomainKeyReport::parse(record.as_bytes()).unwrap(),
695                expected_result
696            );
697        }
698    }
699}