Hiya,

I don't think the DKIM WG really needs to ask this question. ISTM,
the answer is relatively obvious: recommend signing with both a
current alg (e.g. RSA/eddsa) and ML-DSA.

Perhaps the more interesting question is how to convince the many
domains that haven't changed their DKIM signing key in years, to
start using DKIM2 and adding a 2nd ML-DSA sig.

Cheers,
S.

On 19/06/2026 19:10, Wei Chuang wrote:
Hi,
At the Wednesday, June 17th DKIM interim, I asked if the working group
would be interested in working on PQC for DKIM/DKIM2.  Google feels a PQC
migration is necessary by 2029
<https://blog.google/innovation-and-ai/technology/safety-security/cryptography-migration-timeline/>
which
is much sooner than many had anticipated.  Richard pointed out that based
on the low adoption of ed25519-sha256 in DKIM, there needs to be a forcing
function to deploy a new algorithm.  The best time to do this would be
during the DKIM2 rollout.  Murray pointed out that none of us are PQC
experts, which no one disagreed with, and we would need CFRG's
<https://datatracker.ietf.org/rg/cfrg/about/> help in picking a candidate
algorithm.  He asked for a threat model to give to CFRG to help them
identify the right characteristics for a PQC DKIM candidate algorithm.

We've written the following DKIM threat model as a starting point:

The DKIM Working Group requests guidance from the CFRG in identifying the
most appropriate Post-Quantum Cryptography (PQC) digital signature
algorithm for DomainKeys Identified Mail. Our primary threat model focuses
on an adversary utilizing quantum analytic key compromise to forge
signatures, thereby enabling widespread domain spoofing. To maintain the
reliability of global email delivery, any proposed algorithm must navigate
DKIM's strict operational constraints: public keys are distributed via DNS
TXT records (imposing severe sensitivity to UDP payload limits and TCP
fallback latency), and signatures are transmitted within standard email
headers. Furthermore, DKIM’s existing architecture evaluates the message
hash independently of the signature generation to facilitate the processing
of streamed email bodies. We seek CFRG’s expertise in selecting an
algorithm that optimizes for these stringent size constraints while
providing secure, practical recommendations for accommodating our
pre-hashed input model.

We welcome feedback on the above threat model for the CFRG.

Thanks,
-Wei


_______________________________________________
Ietf-dkim mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

_______________________________________________
Ietf-dkim mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to