If they're failing because it says "message has been modfied" that
should be all the hint you need.  Sendmail conflates submission and
relay, and has a sometimes unfortunate tendency to helpfully clean up
message headers on the way through, which of course breaks DKIM
signatures.  I haven't run sendmail in 20 years but as I recall there
should be some way to run submitted mail through sendmail once to
clean up the headers, then DKIM sign it, then send it along for relay.
That's what everyone else does.


