This is only true if the alignment between the d field and the mf/rt fields are 
possible, Wei and also I want to solve the synthetik mailflows that happen with 
3rd party providers.

Case 1: Is the Bulk Mail Providers want to sign as the 2nd or 3rd hop, but then 
need to introduce synthetic targets, that are more related to VERP but bring no 
benefit to most of the real world situations of Bulk Mail provider.

Case 2: Cloud SEG businesses often sit in front of the Mailboxprovider in the 
Enterprise environment and should be able sign their hop even if they don't 
have alignment.

In both cases the assert is need to not open the door to replay attacks.

--

Best regards,
Tobias Herkula

________________________________
From: John Levine <[email protected]>
Sent: 29 May 2026 22:40
To: [email protected] <[email protected]>
Cc: Tobias Herkula <[email protected]>
Subject: Re: [Ietf-dkim] Re: DKIM2 Multiple Domain Signatures Proposal

It appears that Tobias Herkula  <[email protected]> said:
>A DKIM2 signature i=n could explicitly assert the signing domain expected to 
>produce DKIM2 signature i=n+1. Alternatively, a DKIM2 signature
>i=n could explicitly assert the signing domain of DKIM2 signature i=n-1 as the 
>domain it continues from. In both cases, the assertion MUST be
>covered by the DKIM2 signature instance that makes it and therefore protected 
>against modification.

It already does that with the mf= and rt= fields.

See sections 8.2, 8.3, and 10.4 of draft-ietf-dkim-dkim2-spec-02

R's,
John
_______________________________________________
Ietf-dkim mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to