On 21 Apr 2021, at 17:39, Wayne via Exim-users wrote:

Then I assume the body is being signed implicitly no matter what headers
are selected?

Yes. A DKIM signature technically signs a selected set of headers and of a hash of the body, both in a canonicalized form. Without the body hash, it would be trivial to forge a signature by replicating the headers and signature of any signed message.

--
Bill Cole
[email protected] or [email protected]
(AKA @grumpybozo and many *@billmail.scconsult.com addresses)
Not Currently Available For Hire

--
## List details at https://lists.exim.org/mailman/listinfo/exim-users
## Exim details at http://www.exim.org/
## Please use the Wiki with this list - http://wiki.exim.org/

Reply via email to