I couldn't find prior discussion about this, if I missed it somehow could
someone cluestick me?

We've been working with Murray on openarc, and there are some chain
validation failure modes that closely resemble a dkim tempfail (for
instance, DNS unresponsiveness when trying to query for a key).

Right now, these create chain states of cv=fail.

We believe this is the correct behavior, as a message in transit amongst
multiple hops cannot cleanly have a temporary error retried, so the
temporary failure effectively becomes a permanent error for the chain and
cv=fail is justified because the chain is dead from this point forward.

That said, is there any value (especially for final receivers), in
transmitting that this failure was due to a temporary error and not
necessarily a permanent one? And is so, where would this transmission live?

Seth

-- 

[image: logo for sig file.png]

Bringing Trust to Email

Seth Blank | Head of Product for Open Source and Protocols
s...@valimail.com
+1-415-894-2724 <415-894-2724>
_______________________________________________
dmarc mailing list
dmarc@ietf.org
https://www.ietf.org/mailman/listinfo/dmarc

Reply via email to