DKIM / SPF Annotated Email (EML)
An email annotated with DKIM-Signature, Received-SPF, and Authentication-Results headers (all reporting pass) — for testing email-authentication header parsing. The DKIM signature value is a sample placeholder, not real cryptography.
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Return-Path: <maya@brightside.example>
Received-SPF: pass (brightside.example: 203.0.113.7 is authorized)
client-ip=203.0.113.7;
Authentication-Results: mx.meridiansupply.example;
spf=pass smtp.mailfrom=brightside.example;
dkim=pass header.d=brightside.example;
dmarc=pass header.from=brightside.example
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=brightside.example;
s=jan2026; h=from:to:subject:date:message-id;
bh=SAMPLEbodyHashBase64Placeholder=;
b=SAMPLEsignatureBase64Placeholder0000000000000000000000000000000000/PLACEHOLDER=
From: Maya Chen <maya@brightside.example>
To: Sam Rivera <sam@meridiansupply.example>
Subject: Meeting confirmation
Date: Thu, 15 Jan 2026 09:10:00 -0800
Message-ID: <dkim-conf01@brightside.example>
SGkgU2FtLAoKQ29uZmlybWluZyBvdXIgbWVldGluZyBvbiB0aGUgMjB0aC4gVGhpcyBtZXNzYWdl
IGNhcnJpZXMgc2FtcGxlCkRLSU0tU2lnbmF0dXJlLCBTUEYsIGFuZCBBdXRoZW50aWNhdGlvbi1S
ZXN1bHRzIGhlYWRlcnMgZm9yIHRlc3RpbmcgZW1haWwKYXV0aGVudGljYXRpb24gcGFyc2luZy4g
VGhlIHNpZ25hdHVyZSB2YWx1ZSBpcyBhIHBsYWNlaG9sZGVyLCBub3QgcmVhbCBjcnlwdG8uCgpN
YXlhCg==
Specifications
- Headers
- DKIM-Signature, Received-SPF, Authentication-Results, Return-Path
- Note
- DKIM signature is a sample placeholder
What is a .eml file?
An EML file is a single email message stored in the RFC 822 / MIME format — plain-text headers (From, To, Subject, Date, Message-ID) followed by the body, which may be plain text, HTML, or a multipart structure with alternative bodies and file attachments encoded in base64.
How to use this file
Use an example EML to test email header parsing, MIME decoding, HTML-part handling, attachment extraction, and EML-to-other-format conversion.
How to use this file for testing
“DKIM / SPF Annotated Email (EML)” is a deterministic Novus Examples fixture for Email parsing. Standards-compliant RFC 822 messages — plain, multipart text+HTML, and with an attachment — plus an MBOX mailbox, for testing header parsing, MIME decoding, attachment extraction, and mailbox splitting.
Documented properties for this file: EML · 1,163 bytes. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.
Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such — expect parsers to fail loudly rather than silently accept them.
Email fixtures use fixed dates, message IDs, and MIME boundaries so runs are reproducible, and every address is fictional. Test header parsing, MIME decoding, attachment extraction, and EML/MBOX conversion against the documented structure.
Code examples
from email import policy
from email.parser import BytesParser
msg = BytesParser(policy=policy.default).parse(open("dkim-signed.eml", "rb"))
print(msg["subject"], msg["from"])Related files
- emlEML — Authentication-Results: SPF, DKIM and DMARC All FailThe failing twin of the all-pass fixture, headers otherwise identical: SPF fail, DKIM fail with a quoted reason property, DMARC fail under p=REJECT. The quoted reason string contains a semicolon-free phrase specifically to test method-splitting.

- emlEML — Authentication-Results: SPF, DKIM and DMARC All PassThe fully authenticated baseline: SPF pass, DKIM pass, DMARC pass with aligned domains, under a p=REJECT policy. The DKIM signature is a visible SAMPLE placeholder, so the header parses and reports pass but will never verify cryptographically.

- emlEML — dkim=pass but dmarc=fail on Strict AlignmentSPF passes and DKIM passes, yet DMARC fails — because the signing domain is the relay's, not the From domain's, and the policy demands strict alignment. Any dashboard that reports authentication by reading dkim= alone shows this message as trustworthy.

- emlEML — Three Authentication-Results Headers From Three HopsA mailing-list post carrying three Authentication-Results headers stamped by three different hosts, where DKIM passed upstream and failed at the final hop after the list rewrote the message. Only the topmost header, from the receiving host, may be trusted.

- emlEML — Two DKIM-Signature Headers, One With an l= TagTwo DKIM-Signature headers for the same message — the RSA/Ed25519 double-signing used during algorithm migrations — with an l= body-length tag on the first. l= means only the first 120 octets are covered, so anything appended afterwards still verifies; both values are SAMPLE placeholders.

- emlEML — Two-Instance ARC Chain (SAMPLE Seals)A forwarded message carrying a two-instance ARC chain — Seal, Message-Signature and Authentication-Results at i=1 and i=2 — where DKIM broke in transit but ARC records that it passed upstream. Every seal is a visible SAMPLE placeholder, not real cryptography.

Generated by generation/email_extra.py. Free for any use, no attribution required — license.