On Sat, May 16, 2026, at 16:30, G.W. Haywood wrote: > Hi there, > > On Sat, 16 May 2026, Wei Chuang wrote: > > > ... the division of labor ... > > On this one, I'm on the fence. > > > ... > > notifications often have stricter security requirements about who ought to > > be identified with the message i.e. who can modify or extend it. ... > > ... > > I really like the idea that a sender could say "This [List of Lists] > tells you that [these parties] are permitted to make [these changes] > to this message during its transit from the sender to the recipient. > Maybe [List of Lists] could live in the DNS. Just kite-flying here.
There's no value in having such information in the DNS. To the point that this is useful at all, it's more useful to specify "acceptable modifier domains for this message" on a message-by-message basis. You can sign it easily enough. The value of things in the DNS is (IMHO) restricted to how to handle messages which are NOT correctly DKIM2 signed, everything else (including who can modify it, and whether null recipe modifications are acceptable) can be included in the message more flexibly and in a header whos signature persists through any valid chain (since DKIM2-Signature and Message-Instance are always signed and never modified, one of the good bits from the ARC-Seal design which we have kept). -- Bron Gondwana, CEO, Fastmail Pty Ltd / Fastmail US LLC [email protected]
_______________________________________________ Ietf-dkim mailing list -- [email protected] To unsubscribe send an email to [email protected]
