On Wed, Apr 29, 2015 at 10:16 AM, Hector Santos <[email protected]> wrote:

> I downloaded OpenDKIM source code to see whats it offers. I believe I saw:
>
> o ADSP was no longer supported, pulled. Grep showed one instance of an
> inline comment referring to ADSP.
>

Correct.


> o ATPS was offered, but I failed to see how it was hooked into ADSP
> because it ADSP was pulled.
>

It has nothing to do with ADSP.

o DMARC was offered.
>

OpenDKIM doesn't know anything about DMARC other than the fact that
"dmarc=" is an Authentication-Results field is not a syntax error.
OpenDKIM runs in the milter stream before OpenDMARC does, and OpenDMARC
consumes the results OpenDKIM provides.


> ATPS was suppose to be based off the ADSP record with the optional tag
> "atps=y" I believe that is how it worked.  If the "atps=y" was present in
> the ADSP record, then ATPS was supported and an ATPS_Hash(ADID, SDID)
> lookup was done.
>

Nope.  See RFC6541.


> If OpenDKIM is popular among many big systems, it would make sense to
> slightly update OpenDKIM so that the "atps=y" option is based off a DMARC
> lookup.   The change is small.
>

Sure, if that's consensus.  That would also involve promoting ATPS to the
Standards Track, but to do that we'd need to see some hope that widespread
deployment is likely.  But we still have that pesky registration problem to
deal with.


> Maybe Murray can explain how its setup and triggered in OpenDKIM.
>

If you enable it, you just have to name which domains you authorize to sign
for you.

-MSK
_______________________________________________
dmarc mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dmarc

Reply via email to