On Fri, Jun 19, 2026 at 8:14 PM Wei Chuang <weihaw=
[email protected]> wrote:

> We've written the following DKIM threat model as a starting point:
>
> The DKIM Working Group requests guidance from the CFRG in identifying the
> most appropriate Post-Quantum Cryptography (PQC) digital signature
> algorithm for DomainKeys Identified Mail. Our primary threat model focuses
> on an adversary utilizing quantum analytic key compromise to forge
> signatures, thereby enabling widespread domain spoofing. To maintain the
> reliability of global email delivery, any proposed algorithm must navigate
> DKIM's strict operational constraints: public keys are distributed via DNS
> TXT records (imposing severe sensitivity to UDP payload limits and TCP
> fallback latency), and signatures are transmitted within standard email
> headers. Furthermore, DKIM’s existing architecture evaluates the message
> hash independently of the signature generation to facilitate the processing
> of streamed email bodies. We seek CFRG’s expertise in selecting an
> algorithm that optimizes for these stringent size constraints while
> providing secure, practical recommendations for accommodating our
> pre-hashed input model.
>
> We welcome feedback on the above threat model for the CFRG.
>

There were several replies to this.  Given those replies, it's unclear to
me whether we should present the text as-is to Paul or if those replies
included or suggested changes we need to incorporate first.

Can we get some guidance here, particularly from people that replied
upthread?

-MSK
_______________________________________________
Ietf-dkim mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to