On Wed, Aug 5, 2026 at 10:15 AM John Levine <[email protected]> wrote:

> It appears that Hannah Stern  <[email protected]> said:
> >Hi!
> >
> >The draft contains a t=s flag, described like this:
> >
> >   s
> >   : Any DKIM2 signature header fields using the "i=" tag MUST have
> >     the same domain value on the right-hand side of the "@" in the
> >     "i=" tag and the value of the "d=" tag. That is, the "i="
> >     domain MUST NOT be a subdomain of "d=". Use of this flag is
> >
> >    RECOMMENDED unless subdomaining is required.
> >
> >However, in the DKIM2 main draft, the i= tag means something completely
> >different, so this makes no sense at all? Can this paragraph be just
> >removed from the draft?
>
> Looks like a leftover from DKIM1 and its useless i= tag which puported to
> identify individual users in a domain.  I agree it should go.
>

Sure that sounds good to me.  My plan was to state that it is deprecated
for DKIM2, rather than deleting the text.  Indeed this text is a leftover
from DKIM1 where consensus wasn't clear, but glad it's being clarified.

What about deprecating "t=y" (the testing declaration domain flag) for
DKIM2?  Then the entire Flags section can be deprecated.  We've seen issues
with "t=y" for DKIM1 where domains appear to use it on what look like
production keys.

-Wei
_______________________________________________
Ietf-dkim mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to