> I guess it's a matter of preference, as I'd rather defer on NXDOMAIN and try 
> at least once more if for example the key record somehow hasn't propagated 
> yet.

I see your point, but working around the incompetent only encourages them.

If anyone's collecting stuff to put in the next version of the deployment 
document, we should encourage people to check that their DNS servers are 
serving the key records before using them in outgoing mail.  I install 
mine a couple of days ahead, just to be on the safe side.

Regards,
John Levine, [email protected], Taughannock Networks, Trumansburg NY
"I dropped the toothpaste", said Tom, crestfallenly.
_______________________________________________
dkim-ops mailing list
[email protected]
http://mipassoc.org/mailman/listinfo/dkim-ops

Reply via email to