On Mar 15, 2006, at 4:22 PM, Michael Thomas wrote:
John Levine wrote:
And then what? What would you have my receiver do differently
just because some random third party inserted a signature?
If it's a third party with a good reputation, [...]
And here's where we go off the rails. DKIM isn't doing reputation,
and making assumptions that reputation will save you is *every* bit
as speculative as making assumptions that mailing list software
will change.
For the most part, phishers do not attack unknown domains. Such
domains, irrespective of the From address, are recognized by the
message content. Better than 95% of the phishing exploits are
blocked through rather simple message content heuristics, where
DomainKeys or DKIM improves this figure substantially. This is not
reputation in the traditional sense. Perhaps recognition would be a
better term.
-Doug
_______________________________________________
NOTE WELL: This list operates according to
http://mipassoc.org/dkim/ietf-list-rules.html