[mail.inbound] require_dkim makes gitbayd verify a reply's DKIM signature itself (go-msgauth; rsa-sha256 >= 1024 bits and ed25519; l= and sha1 refused; keys from DNS with a 5s timeout, cached 15 minutes; a temporary DNS failure retries). A reply is accepted when a signature verifies with d= in relaxed alignment with From, and From, To or Cc carrying the reply address, Message-ID and Content-Type are all signed; an unsigned Content-Transfer-Encoding is accepted only as 7bit, 8bit or binary. Either this or trusted_authserv_id suffices. Every reply's raw header is checked first: field names must be printable ASCII with no space before the colon, one From, at most one To, Cc, Message-ID, Content-Type and Content-Transfer-Encoding. Dedupe also keys on each passing signature. Admin/Threat-Model/CHANGELOG, FuzzDKIM in audit.sh.
Closes #307