On Fri, Jun 19, 2026 at 8:14 PM Wei Chuang <weihaw= [email protected]> wrote:
> We've written the following DKIM threat model as a starting point: > > The DKIM Working Group requests guidance from the CFRG in identifying the > most appropriate Post-Quantum Cryptography (PQC) digital signature > algorithm for DomainKeys Identified Mail. Our primary threat model focuses > on an adversary utilizing quantum analytic key compromise to forge > signatures, thereby enabling widespread domain spoofing. To maintain the > reliability of global email delivery, any proposed algorithm must navigate > DKIM's strict operational constraints: public keys are distributed via DNS > TXT records (imposing severe sensitivity to UDP payload limits and TCP > fallback latency), and signatures are transmitted within standard email > headers. Furthermore, DKIM’s existing architecture evaluates the message > hash independently of the signature generation to facilitate the processing > of streamed email bodies. We seek CFRG’s expertise in selecting an > algorithm that optimizes for these stringent size constraints while > providing secure, practical recommendations for accommodating our > pre-hashed input model. > > We welcome feedback on the above threat model for the CFRG. > There were several replies to this. Given those replies, it's unclear to me whether we should present the text as-is to Paul or if those replies included or suggested changes we need to incorporate first. Can we get some guidance here, particularly from people that replied upthread? -MSK
_______________________________________________ Ietf-dkim mailing list -- [email protected] To unsubscribe send an email to [email protected]
