ietf-dkim
[Top] [All Lists]

Re: [ietf-dkim] Requirements on how SSP stuff is found...

2006-07-31 06:09:53
I'll take a crack at this one.

> I suggest that we need to explain the basis for that assumption and
> that the explanation needs to provide the empirical basis for
> believing that it is the right choice.

The "From:" header value is the identity the naive user assumes to be the originator due to the vast majority of mail clients which have trained them to assume so. Thus it has a property, for better or worse, which no other header has. Therefore, from a domain owners point of view (who is interested in protecting the integrity of his domain in the minds of naive users as far as possible), "From:" header value seems a wise selection.

> In other words, how is it supposed to be used/useful

It's useful if understood from the domain owners point of view. The domain owner wishes to be "consulted" concerning their signing practice if their domain is being presented by the MUA to an end user. At least, this is the capability I think SSP is trying to provide to domain owners.

I'm sure I'm not understanding some fundamentals and problems hidden in all this but I'm equally sure that I will receive and will welcome some educating.

--
Arvel



_______________________________________________
NOTE WELL: This list operates according to http://mipassoc.org/dkim/ietf-list-rules.html