On Thu, May 28, 2026 at 11:13 AM Vittorio <[email protected]> wrote: > the current dkim2 specification excludes all X-* headers from the signed > header set. I would like to propose a refinement. > X-* headers fall into two categories with different security properties. > Vendor diagnostic telemetry (X-MS-*, X-GM-* and similar) is legitimately > stripped at domain boundaries and should remain excluded. Operational > metadata (antispam scores, authenticated user identities, compliance > annotations) carries security-relevant information that an attacker can > inject or manipulate without invalidating the DKIM2 signature under the > current blanket exclusion. > The proposed change: replace the blanket X-* exclusion with prefix-based > exclusion. Headers matching well-known vendor diagnostic prefixes are > excluded. All other X-* headers are included in the signed set. The list > of excluded prefixes SHOULD be operator-configurable. > This is documented in more detail in Section 7.5.1 of > draft-moccia-dkim2-deployment-profile-04 (2026-05-23).
How would one keep their list of "well-known vendor diagnostic prefixes" current? Wouldn't this require that both signer and verifier have that list in sync? -MSK
_______________________________________________ Ietf-dkim mailing list -- [email protected] To unsubscribe send an email to [email protected]
