On Thu, May 28, 2026 at 11:13 AM Vittorio <[email protected]> wrote:

> the current dkim2 specification excludes all X-* headers from the signed
> header set. I would like to propose a refinement.
> X-* headers fall into two categories with different security properties.
> Vendor diagnostic telemetry (X-MS-*, X-GM-* and similar) is legitimately
> stripped at domain boundaries and should remain excluded. Operational
> metadata (antispam scores, authenticated user identities, compliance
> annotations) carries security-relevant information that an attacker can
> inject or manipulate without invalidating the DKIM2 signature under the
> current blanket exclusion.
> The proposed change: replace the blanket X-* exclusion with prefix-based
> exclusion. Headers matching well-known vendor diagnostic prefixes are
> excluded. All other X-* headers are included in the signed set. The list
> of excluded prefixes SHOULD be operator-configurable.
> This is documented in more detail in Section 7.5.1 of
> draft-moccia-dkim2-deployment-profile-04 (2026-05-23).


How would one keep their list of "well-known vendor diagnostic prefixes"
current?

Wouldn't this require that both signer and verifier have that list in sync?

-MSK
_______________________________________________
Ietf-dkim mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to