Hiya,
I don't think the DKIM WG really needs to ask this question. ISTM, the answer is relatively obvious: recommend signing with both a current alg (e.g. RSA/eddsa) and ML-DSA. Perhaps the more interesting question is how to convince the many domains that haven't changed their DKIM signing key in years, to start using DKIM2 and adding a 2nd ML-DSA sig. Cheers, S. On 19/06/2026 19:10, Wei Chuang wrote:
Hi, At the Wednesday, June 17th DKIM interim, I asked if the working group would be interested in working on PQC for DKIM/DKIM2. Google feels a PQC migration is necessary by 2029 <https://blog.google/innovation-and-ai/technology/safety-security/cryptography-migration-timeline/> which is much sooner than many had anticipated. Richard pointed out that based on the low adoption of ed25519-sha256 in DKIM, there needs to be a forcing function to deploy a new algorithm. The best time to do this would be during the DKIM2 rollout. Murray pointed out that none of us are PQC experts, which no one disagreed with, and we would need CFRG's <https://datatracker.ietf.org/rg/cfrg/about/> help in picking a candidate algorithm. He asked for a threat model to give to CFRG to help them identify the right characteristics for a PQC DKIM candidate algorithm. We've written the following DKIM threat model as a starting point: The DKIM Working Group requests guidance from the CFRG in identifying the most appropriate Post-Quantum Cryptography (PQC) digital signature algorithm for DomainKeys Identified Mail. Our primary threat model focuses on an adversary utilizing quantum analytic key compromise to forge signatures, thereby enabling widespread domain spoofing. To maintain the reliability of global email delivery, any proposed algorithm must navigate DKIM's strict operational constraints: public keys are distributed via DNS TXT records (imposing severe sensitivity to UDP payload limits and TCP fallback latency), and signatures are transmitted within standard email headers. Furthermore, DKIM’s existing architecture evaluates the message hash independently of the signature generation to facilitate the processing of streamed email bodies. We seek CFRG’s expertise in selecting an algorithm that optimizes for these stringent size constraints while providing secure, practical recommendations for accommodating our pre-hashed input model. We welcome feedback on the above threat model for the CFRG. Thanks, -Wei _______________________________________________ Ietf-dkim mailing list -- [email protected] To unsubscribe send an email to [email protected]
OpenPGP_signature.asc
Description: OpenPGP digital signature
_______________________________________________ Ietf-dkim mailing list -- [email protected] To unsubscribe send an email to [email protected]
