thank you very much for your assistance. DKIM, SPF, and DMARC records are up and working.
$ amavisd genrsa /etc/pki/tls/private/example.com-dkim.key.pem
$ chgrp amavis /etc/pki/tls/private/example.com-dkim.key.pem
$ chmod g+r /etc/pki/tls/private/example..com-dkim.key.pem
$ mkdir -p /etc/e-smith/templates-custom/etc/amavisd.conf
$ nano /etc/e-smith/templates-custom/etc/amavisd.conf/95dkim
#filippo enable dkim
$enable_dkim_verification = 1;
$enable_dkim_signing = 1;
$log_level = 5;
dkim_key('example.com', 'dkim', '/etc/pki/tls/private/example.com-dkim.key.pem');
@dkim_signature_options_bysender_maps = ( \{ '.' => \{ ttl => 21*24*3600, c => 'relaxed/simple' \} \} );
$ signal-event nethserver-mail-filter-update
$ signal-event nethserver-mail-server-update
$ amavisd -u amavis -g amavis -c /etc/amavisd.conf showkeys
https://support.google.com/a/answer/2466563?hl=en - used for DMARC
http://www.mailradar.com/spf/ - used for SPF