ietf-dkim
[Top] [All Lists]

Re: [ietf-dkim] protecting domains that don't exist

2008-04-15 04:27:53
On Mon, 14 Apr 2008 21:52:43 +0100, John Levine <johnl(_at_)iecc(_dot_)com> 
wrote:

Two more observations: One is the assumption that mail from subdomains
is somehow automatically equivalent to mail from the enclosing domain.
I don't see any reason for this to be true.  I have one opinion about
mail from foo(_at_)aol(_dot_)com, and a rather lower opinion of mail from
foo(_at_)327cb72e(_dot_)ipt(_dot_)aol(_dot_)com, without needing any help 
from ADSP.

OTOH, the converse is likely to be relevant to quite a lot of domains,  
even if it does not apply to aol.com.

The other is that if you're so desperate to provide complete ADSP
coverage of subdomains, you can do it right now with a specialized DNS
server that does the equivalent of synthesizing names from
_adsp._domainkey.*.example.com.  This is no worse a hack than the
sorta kinda approaches, but unlike all of them, it would actually
work.

Yes, that look interesting. But presumably it is more or less equivalent  
to doing the full tree walk and then cacheing the result (being careful to  
observe TTL).

-- 
Charles H. Lindsey ---------At Home, doing my own thing------------------------
Tel: +44 161 436 6131                       
   Web: http://www.cs.man.ac.uk/~chl
Email: chl(_at_)clerew(_dot_)man(_dot_)ac(_dot_)uk      Snail: 5 Clerewood Ave, CHEADLE, SK8 3JU, U.K.
PGP: 2C15F1A9      Fingerprint: 73 6D C2 51 93 A0 01 E7 65 E8 64 7E 14 A4 AB A5
_______________________________________________
NOTE WELL: This list operates according to 
http://mipassoc.org/dkim/ietf-list-rules.html

<Prev in Thread] Current Thread [Next in Thread>