>I'm beginning to lean towards liking the "embedded message" solution that
>mailman has, though.  In my testing, it works mostly fine in Gmail, though
>it assumes (and prefixes with) "forwarded message".  YMail's handling isn't
>that pretty, however, as it ignores the headers of the embedded message
>completely.

I meant to ask, what's your spear phish strategy here?  Do you expect
to see a valid DKIM signature on the internal message?  Or do you just
treat it as a digest and not look inside the wrapper?  Or something
else?

>From what I can see on the mailman lists, looking for the internal
DKIM signatures won't work too well, since mailman sometimes removes
parts from multipart/alternative to fix to some formatting issue.
Yahoo's mail is apparently particularly likely to need this.

R's,
John

_______________________________________________
dmarc mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dmarc

Reply via email to