It appears that Tobias Herkula <[email protected]> said: >A DKIM2 signature i=n could explicitly assert the signing domain expected to >produce DKIM2 signature i=n+1. Alternatively, a DKIM2 signature >i=n could explicitly assert the signing domain of DKIM2 signature i=n-1 as the >domain it continues from. In both cases, the assertion MUST be >covered by the DKIM2 signature instance that makes it and therefore protected >against modification.
It already does that with the mf= and rt= fields. See sections 8.2, 8.3, and 10.4 of draft-ietf-dkim-dkim2-spec-02 R's, John _______________________________________________ Ietf-dkim mailing list -- [email protected] To unsubscribe send an email to [email protected]
