… as long as the secret sauce header isn’t encoded in a x-something header.
But then it is entirely up to you to determine which headers you sign,
overriding the defaults, right?
No. See draft-ietf-dkim-dkim2-spec-02, section 5.2.
R's,
John
From: John Levine <[email protected]>
Date: Wednesday, 10 June 2026 at 2:29 PM
To: [email protected] <[email protected]>
Cc: [email protected] <[email protected]>
Subject: [Ietf-dkim] Re: [EXTERNAL] Re: Proposed change: X-* header handling in
signed header set
It appears that Wei Chuang <[email protected]> said:
-=-=-=-=-=-
What about keeping the DKIM2 exclusion of X- header fields, and
standardizing a new prefix for proprietary headers that can be optionally
protected?
The current plan is to sign everything except X-* and a short list of trace
headers.
So if you add:
Google-secret-sauce: 42swordfish
that'll get signed.
I don't see a problem here to be solved.
_______________________________________________
Ietf-dkim mailing list -- [email protected]
To unsubscribe send an email to [email protected]