It appears that William Weiner <[email protected]> said: >-=-=-=-=-=- > >Pietro's reading is correct: EMail Parrot and similar services start a new >DKIM2 chain at i=1, and the spec >handles that cleanly. No new protocol mechanism is needed. The BCP question is >narrower - whether receivers should >have normative guidance on evaluating that pattern as the category grows.
As I may have said a few dozen times, the answer is still no. >The DMARC parallel is the direct precedent - and the lesson is not that Yahoo >acted in bad faith. Yahoo was >getting hammered with spoofed @yahoo.com phishing and p=reject was the only >tool the spec gave them. The BCP had >not defined a compliant path for mailing lists, so Yahoo had no option that >protected their users without breaking >lists. Nope. Yahoo could have left their DMARC record alone and adjusted their own mail servers to reject mail with a Yahoo return address and no Yahoo DKIM signature. But it was slightly easier to change the DMARC record and as their CEO said at at the time, she did not care that it broke all the mailing lists. As I presume you're aware, we invented ARC to try to provide a way for mailing lists to say what they did, so receivers could look back and see if the message was originally signed and DMARC aligned. But ARC turns out not to work (see the recent discussions in the DMARC WG) because they're tricky enough that even Google gets them wrong. DKIM2 is basically ARC but with each intermediate step showing its work so you don't have to trust them. Anyway, we're going in circles here. Please propose specific text for the DKIM2 draft and we can see if there is any support for adding it. If so we can add it, if not, we can stop. R's, John _______________________________________________ Ietf-dkim mailing list -- [email protected] To unsubscribe send an email to [email protected]
