On Thu, Sep 24, 2020 at 1:37 AM Murray S. Kucherawy <[email protected]>
wrote:

> On Wed, Sep 23, 2020 at 2:56 PM Seth Blank <seth=
> [email protected]> wrote:
>
>> The original question in this thread had two parts:
>>
>> "Is it desirable to clarify this language, [1] such that it is clear
>> which DKIM keys are required to include in a report, and [2] if so, how
>> should the appropriate keys be determined?"
>>
>> I hear consensus on [1], that the domain and selector of the key used to
>> evaluate the DMARC status MUST be included, but on [2] there is not yet
>> clear consensus.
>>
>
> It's late and tomorrow's coffee is still some five hours away, but:
>
> a) Isn't the answer to [2] explicit in DMARC?  If there's an aligned
> signature, you use that.
>

It's not, see the original threads and notes from Elizabeth. Further, there
are multiple large-scale real world implementations that get this wrong, so
additional clarity would seem to be needed.


> b) Did you really mean "keys"?  Or should this be "domains and selectors"?
>

Domains and selectors.


> -MSK
>


-- 

*Seth Blank* | VP, Standards and New Technologies
*e:* [email protected]
*p:* 415.273.8818


This email and all data transmitted with it contains confidential and/or
proprietary information intended solely for the use of individual(s)
authorized to receive it. If you are not an intended and authorized
recipient you are hereby notified of any use, disclosure, copying or
distribution of the information included in this transmission is prohibited
and may be unlawful. Please immediately notify the sender by replying to
this email and then delete it from your system.
_______________________________________________
dmarc mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dmarc

Reply via email to