Hello everyone, I’m new to this list, please bear with me when ask stupid 
question..!

We are implementing an email encryption gateway, and we are currently looking 
at how to implement DKIM properly under these circumstances. The challenge is 

gateway receives a DKIM signed email
gateway can verify DKIM
gateway encrypts emails —> DKIM is broken now
gateway forwards email to the receiving mailserver
mailserver sees a broken DKIM

Looking at the lastest draft, I am not sure if this scenario has been 
considered. I found the null recipe concept, which might be the intended way to 
handle this. 

However, using a null recipe seems to break the chain, unless there is 
something like a trusted server (or gateway, in this case) that is allowed to 
introduce a non-reversible transformation.

Am I on the right track? 

Thanks
Metin

Attachment: smime.p7s
Description: S/MIME cryptographic signature

_______________________________________________
Ietf-dkim mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to