❦ 23 septembre 2016 16:15 CEST, Thomas Goirand <z...@debian.org> :

>> The "[Python-modules-team]" thing in the subject is probably enough to
>> break the DKIM signature.
>
> I don't believe DKIM signature is done on the header+body. If I'm not
> mistaking, it's done only in the body of the mail, because each SMTP
> server on the way to your inbox can add a "Received:" field, so you can
> trace the email.
>
> So yes, footers in emails can break stuff, but not mangling subject,
> which is part of the metadata.

DKIM can also be done on the headers (and usually is). The DKIM
signature contains the list of headers that were used for the
signature. See the headers of the message from Sandro:

#v+
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=gmail.com; s=20120113;
        h=mime-version:sender:in-reply-to:references:from:date:message-id
         :subject:to:cc;
        bh=aIVZ7A5RI8js3S6zxiwDgAgKRvn7VlX7UW8naQXAUxk=;
        b=yWundTut0iTb/fNwkvU0hu4v5+s6vQW/pZN4gGZQpV7exzsUGKHjYs8BTCobNWvpEI
         DugPdBz8MszdzoibvUW6vNij26BS+uh6xFmBfUj26xAWJKGpXzYvqGkfQ2FfTkZi6Dvf
         PlBuHkrzyt8E8FoiD9i+ZIy5VTEV0FeS2KCbVwhU/dflrzxbkwr4eTZLsTU2TTy9OaXL
         Mw44tf8xU4NhlVJGzAsUyX/p+epTHuSMb82l6oyiioTOoJ9Uc2aBWigyv2OTjFas4B/G
         EuBKBSwGPQuav9ghqFbaACngF5Mny5dyFEbKI8/oRB/no8IHWVRe+sYti8yL2fuyDG6U
         SIag==
#v-
-- 
Test input for validity and plausibility.
            - The Elements of Programming Style (Kernighan & Plauger)

Attachment: signature.asc
Description: PGP signature

Reply via email to