ietf-dkim
[Top] [All Lists]

Re: [ietf-dkim] The URL to my paper describing the DKIM policy options

2006-07-27 17:03:10
On 27 Jul 2006, at 4:01 PM, Scott Kitterman wrote:

To clarify, by me, I meant my domain. The problem is that in this type of scenario, there is no way to externally distinguish between mail actually
sent by the vanity domain owner and mail sent by another customer of
isp.example.com


I would phrase it as a "situation" or "issue" rather than a "problem."

However, it's not strictly true. Example.com is supposed to be signing the "From" header field. (Section 5.4: "The From header field MUST be signed....") If the From line from your domain is different from the other customers, then it can be distinguished.

This is really an internal ISP operational problem (they need to
sort out who
is allowed to use what identities on their servers), but the
protocol and
associated guidance need to make that clear.

How is it not clear now?

I'm not sure yet. At this point we're just talking about requirements and if
this type of requirement is covered through policy or not.

I think it's covered in the *syntax*.

        Jon

_______________________________________________
NOTE WELL: This list operates according to http://mipassoc.org/dkim/ietf-list-rules.html

<Prev in Thread] Current Thread [Next in Thread>