ietf-dkim
[Top] [All Lists]

[ietf-dkim] When i= domain != d= domain

2006-04-25 15:10:33
,---
| d= The domain of the signing entity (plain-text; REQUIRED).  This
|    is the domain that will be queried for the public key.  This
|    domain MUST be the same as or a parent domain of the "i=" tag
|    (the signing identity, as described below).  When presented with
|    a signature that does not meet this requirement, verifiers MUST
|    either ignore the signature or reject the message.
'___

: d= The domain of the signing entity (plain-text; REQUIRED).  This
:    is the domain that will be queried for the public key.  This
:    domain MUST be the same as or a parent domain of the "i=" tag
:    (the signing identity, as described below).  When presented with
:    a signature that does not meet this requirement, verifiers MUST
:    consider the signature invalid.


Rather than suggesting the remedy of ignoring or rejecting the message, the signature should be defined as invalid. Perhaps this represents some future version of the DKIM protocol, where a backward compatible signature may also be present. It seems defining the state of the signature rather than possible remedies would be more useful.

-Doug






_______________________________________________
NOTE WELL: This list operates according to http://mipassoc.org/dkim/ietf-list-rules.html