http://issues.apache.org/SpamAssassin/show_bug.cgi?id=5378





------- Additional Comments From [EMAIL PROTECTED]  2007-03-29 16:23 -------
While I'm very favorable to rejeting messages from paypal/ebay that aren't 
signed, they haven't updated 
their DNS records to indicate that they're out of the "test mode":

[powerbook:~] gfk% host -t txt _domainkey.paypal.com
_domainkey.paypal.com text "t=y\; o=~"
[powerbook:~] gfk% host -t txt dkim._domainkey.paypal.com
dkim._domainkey.paypal.com text "v=DKIM1\; k=rsa\; t=y\; 
p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQD3j+gKW1qBM+psRHXAdR7tI9QcKW0Ii723AzyTO
4nrVmuJoKWHLoEEQw/
Nc4XF7iyhfadorjqZZ9f+qDXQiKPyLJyVXs0qLrnJQ9BWlQP0xIiz7CTcoHwEhJ1XwgUI/2V6bNghMrnK2yiR/
Vqt5lV5kx4+n1656EefGuOTuNmIWwIDAQAB"

>From draft-delany-domainkeys-base-02.txt, section 3.2.3:
t = a set of flags that define boolean attributes. Valid
        attributes are:

        y = testing mode. This domain is testing DomainKeys and
            unverified email MUST NOT be treated differently from
            verified email. Recipient systems MAY wish to track
            testing mode results to assist the sender.)

        This tag is optional.

So I think that they should remove the t=y tag before we start scoring unsigned 
messages from them. 
Also, there's already a DomainKeys plugin 
(Mail::SpamAssassin::Plugin::DomainKeys) so it might not be 
too hard to implement.



------- You are receiving this mail because: -------
You are the assignee for the bug, or are watching the assignee.

Reply via email to