Lots of threads on this and I think I agree with the team that the x-* headers 
are generally specific to the services and in some cases, we rename them, 
replace them etc. which will create a wave of problems with the unwinding. I 
would much rather stick with the general logic of not sign the x- headers or 
have some list somewhere that we have to maintain and read to make sure we are 
handling these headers differently.

Keeping this simple seems like the right approach.


Regards,

Ross.



________________________________
From: John Levine <[email protected]>
Sent: Friday, June 5, 2026 3:00 PM
To: [email protected] <[email protected]>
Cc: [email protected] <[email protected]>
Subject: [EXTERNAL] [Ietf-dkim] Re: Proposed change: X-* header handling in 
signed header set

It appears that Vittorio  <[email protected]> said:
>X-Authenticated-User: [email protected] generates no signal at all. This
>proposal does not ask to sign all X-* headers. It asks the working group
>to converge on a fixed subset of X-* headers related to spam
>classification, virus scanning and delivery tracking that should be
>included in the signed set.

I can't speak for the rest of the WG, but as far as I'm concerned that
subset is empty.  There is no evidence that you can tell anything reliable
from other people's X- headers, as Richard has repeatedly pointed out.

If you still think this is useful, it's up to you to do the work.

R's,
John

_______________________________________________
Ietf-dkim mailing list -- [email protected]
To unsubscribe send an email to [email protected]
_______________________________________________
Ietf-dkim mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to