Together with DMARC p=none as DKIM signature-presence is ignored and thus
any email can pass.


I don't understand.

Me neither. I still don't see any reason to revisit this issue. Nothing has changed since the last time we argued about it.

R's,
John

PS:

About RFC 5617

At that time, when DKIM deployment was low (though I have had DKIM since
2009 at least) and DMARC did not exist/heavy-use... it thus got marked
historic again. It was also another separate TXT entry to check.

That's not how I remember it.  The potential side effects of demanding a
valid signature on all messages were discouraging enough that ADSP never
saw any serious uptake.  We documented this in RFC 6377 and proposed some
operational solutions, but (as you can see from this list's discussions
over the years), it's still a problem today.

I'm one of the authors of 5617 and that's the way I remember it too. There was and is no way other than a repuation system to tell whether to take a domain's ADSP seriously, and if you have the reputation, you don't need ADSP.

_______________________________________________
dmarc mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dmarc

Reply via email to