> I guess it's a matter of preference, as I'd rather defer on NXDOMAIN and try > at least once more if for example the key record somehow hasn't propagated > yet.
I see your point, but working around the incompetent only encourages them. If anyone's collecting stuff to put in the next version of the deployment document, we should encourage people to check that their DNS servers are serving the key records before using them in outgoing mail. I install mine a couple of days ahead, just to be on the safe side. Regards, John Levine, [email protected], Taughannock Networks, Trumansburg NY "I dropped the toothpaste", said Tom, crestfallenly. _______________________________________________ dkim-ops mailing list [email protected] http://mipassoc.org/mailman/listinfo/dkim-ops
