ietf-dkim
[Top] [All Lists]

Re: [ietf-dkim] ISSUE: SSP-02: MX Record publishing mandate to reduce DNS overhead for SSP Discovery and to detect fraudulent messages

2008-02-12 03:58:21
On Tue, 12 Feb 2008 03:24:29 -0000, Douglas Otis <dotis(_at_)mail-abuse(_dot_)org> wrote:

4th & 6th Sentence Change to:

For the purposes of this section a "valid SSP record" is one that is
both syntactically and semantically correct; in particular, it must
match the ABNF for a "tag-list", and MUST include a defined "dkim=" tag
and MUST be accompanied by an MX record at the Author Domain.

This query MAY be done in parallel with the query made in step 2.

If the result of this query is an "NXDOMAIN" error, the SSP Checker
MUST return an appropriate error to the Evaluator and terminate the
algorithm.  When the SSP record is returned without there also being
an MX record at the Author Domain, the signature SHOULD BE considered
fraudulent without further DNS transactions being attempted.

+1

--
Charles H. Lindsey ---------At Home, doing my own thing------------------------
Tel: +44 161 436 6131     Web: http://www.cs.man.ac.uk/~chl
Email: chl(_at_)clerew(_dot_)man(_dot_)ac(_dot_)uk      Snail: 5 Clerewood Ave, CHEADLE, SK8 3JU, U.K.
PGP: 2C15F1A9      Fingerprint: 73 6D C2 51 93 A0 01 E7 65 E8 64 7E 14 A4 AB A5
_______________________________________________
NOTE WELL: This list operates according to http://mipassoc.org/dkim/ietf-list-rules.html

<Prev in Thread] Current Thread [Next in Thread>