ietf-dkim
[Top] [All Lists]

Re: [ietf-dkim] protecting domains that don't exist

2008-04-14 15:05:53
Dave Crocker wrote:

I now can't tell whether the focus is on an NXDomain for the
_adsp.<domain> string that is queried for ADSP, or the <domain> 
name to which it is associated.

For dom.example following draft-ietf-dkim-ssp-03#section-4.2.2:

1: dig -ttxt _adsp._domainkey.dom.example. : NXDOMAIN => try 2 + 3
2:                   dig -tmx dom.example. : NXDOMAIN => "nxdomain" 
3:     dig -ttxt _adsp._domainkey.example. : NXDOMAIN => "unknown"

These are separate queries.

And separate results, yes.  Steps 1 and 2 could be swapped, and
step 3 is rather dubious, a slightly different approach could be:

1'                   dig -tmx dom.example. : NXDOMAIN => "nxdomain"
2' dig -ttxt _adsp._domainkey.dom.example. : NXDOMAIN => "unknown"

 Frank

_______________________________________________
NOTE WELL: This list operates according to 
http://mipassoc.org/dkim/ietf-list-rules.html

<Prev in Thread] Current Thread [Next in Thread>