DKIM verification succeeds even if a message has no headers in the "h=" field or if the "From" header is not included in the "h=" list, both of which should be failures cases.
Sample message with empty "h=" attached. This succeeded when testing with latest version (2.5.2).
Empty "h=" msg
Logged In: YES
user_id=1048957
Originator: NO
Try the attached patch, which will be included in 2.5.3.
File Added: PATCH
Proposed patch #2
Logged In: YES
user_id=1048957
Originator: NO
File Added: PATCH
Logged In: YES
user_id=1048957
Originator: NO
Patch included in v2.5.3, now released.