Hi! On 5/17/26 02:25, Vittorio wrote:
the proposal that MTAs forwarding null-recipe or "donotmodify" messages should delete all prior DKIM2 headers and re-sign as themselves is operationally equivalent to breaking the chain of custody, which is the core property DKIM2 provides independently of body recipes. If a node deletes the chain and re-signs as itself, the receiver sees a single-hop message with no history. The originator's identity, the forwarding path, and the envelope binding at each hop will all be gone. For a "donotmodify" message from a high-security domain like irs.gov, this means the receiver can no longer verify that the message originated from irs.gov at all. The flag designed to protect the message's integrity would result in the destruction of its provenance.
You can't stop sites or even people copy&pasting received mail text into a new mail. If the approach of including the full original message as MIME part is taken, verifiers could in theory look into that "deeply".
The alternative is simpler: a node that cannot comply with "donotmodify" should reject the message. This preserves the sender's intent without destroying the chain for downstream verifiers.
I think that's the ideal.
It is also worth noting that chain of custody verification does not require trust in intermediaries. Each hop verifies the previous signature cryptographically before signing its own, so the chain is validated in real time during transit, not reconstructed after the fact by the receiver. This is a property of the signature chain itself, not of body recipes or message algebra.
"Each hop verifies the previous signature" but then the next hop has to trust the previous hop with that in your approach. The final receiver has to trust _each_ previous hop.
With DKIM2 the final receiver can instead verify if the previous hops honestly verified what they got.
Hannah. -- Hannah Stern Software Developer Mail Transfer Development 1&1 Mail & Media Development & Technology GmbH | | | Phone: +49 721 91374-4519 E-Mail: [email protected] | Web: www.mail-and-media.com www.gmx.net www.web.de www.mail.com www.united-internet-media.de Hauptsitz Montabaur, Amtsgericht Montabaur, HRB 5452 Geschäftsführer: Alexander Charles, Dr. Michael Hagenau, Thomas Ludwig, Dr. Verena Patzelt Member of United Internet Diese E-Mail kann vertrauliche und/oder gesetzlich geschützte Informationen enthalten. Wenn Sie nicht der bestimmungsgemäße Adressat sind oder diese E-Mail irrtümlich erhalten haben, unterrichten Sie bitte den Absender und vernichten Sie diese E-Mail. Anderen als dem bestimmungsgemäßen Adressaten ist untersagt, diese E-Mail zu speichern, weiterzuleiten oder ihren Inhalt auf welche Weise auch immer zu verwenden. This e-mail may contain confidential and/or privileged information. If you are not the intended recipient of this e-mail, you are hereby notified that saving, distribution or use of the content of this e-mail in any way is prohibited. If you have received this e-mail in error, please notify the sender and delete the e-mail. _______________________________________________ Ietf-dkim mailing list -- [email protected] To unsubscribe send an email to [email protected]
