Hi there,
On Sat, 16 May 2026, Bron Gondwana wrote:
On Sat, May 16, 2026, at 16:30, G.W. Haywood wrote:
On Sat, 16 May 2026, Wei Chuang wrote:
...
notifications often have stricter security requirements about who ought to
be identified with the message i.e. who can modify or extend it. ...
...
I really like the idea that a sender could say "This [List of Lists]
tells you that [these parties] are permitted to make [these changes]
to this message during its transit from the sender to the recipient.
Maybe [List of Lists] could live in the DNS. Just kite-flying here.
There's no value in having such information in the DNS. To the
point that this is useful at all, it's more useful to specify
"acceptable modifier domains for this message" on a
message-by-message basis. You can sign it easily enough.
The value of things in the DNS is (IMHO) restricted to how to handle
messages which are NOT correctly DKIM2 signed, everything else
(including who can modify it, and whether null recipe modifications
are acceptable) can be included in the message more flexibly and in
a header whos signature persists through any valid chain (since
DKIM2-Signature and Message-Instance are always signed and never
modified, one of the good bits from the ARC-Seal design which we
have kept).
Agreed almost all your points. My only concern is that we seem to be
fastly approaching a state where 99% of mail traffic will be comprised
of headers and that doing everything with signed add-ons to individual
messages will cause much larger increases in the traffic than if some
of the access to that information could be off-loaded. It's possible
we could be talking about orders of magnitude here.
Not, at this stage, that I want to make a big thing of it. We already
have to deal with orders of magnitude more cr@p than actual messages.
--
73,
Ged.
_______________________________________________
Ietf-dkim mailing list -- [email protected]
To unsubscribe send an email to [email protected]