The list headers - List-Id, List-Unsubscribe and similar - are covered by DKIM2 
signature and are observable by any receiver writing policy, so the messages 
are not quite indistinguishable from arbitrary single-hop mail. 

You may be right that receivers will, in practice, treat our privacy relay's 
messages as ordinary single-hop mail. That is precisely the outcome we want. 
The BCP request is not asking receivers to treat re-originating intermediaries 
differently - it is asking the BCP to explicitly confirm that a valid 
single-hop originator signature without a prior chain is the expected and 
correct output of this pattern. If ordinary receiver behavior is already what 
you describe, the sentence costs the WG nothing. If a receiver later writes 
policy that treats "no chain plus threading markers" as a suspicious signal, 
the normative text is what forecloses that interpretation before it spreads.

The DMARC history is the cautionary case. p=reject worked as intended, the harm 
to mailing lists was foreseeable, and the absence of normative BCP protection 
for the mailing list pattern left no lever to push back on. A one-sentence 
statement is cheap insurance against the same dynamic.

William Weiner
Weiner Advanced Development LLC, maker of EMail Parrot (emparrot.com)



From: John R Levine <[email protected]>
To: "William Weiner"<[email protected]>, "Emanuel 
Schorsch"<[email protected]>
Cc: "ietf-dkim"<[email protected]>
Date: Mon, 13 Jul 2026 16:11:08 -0600
Subject: Re: [Ietf-dkim] Re: DKIM2 with message encryption

 > On Mon, 13 Jul 2026, William Weiner wrote: 
 >  
 > > You are right that I overstated the case. Blocking mailing list mail under 
 > > p=reject was the expected behavior from the spec, not an irrational local 
 > > policy. The better lesson is that the spec worked exactly as intended and 
 > > still produced collateral harm to a legitimate use case that wasn't 
 > > protected by the BCP - and the workarounds required after the fact were 
 > > worse than prevention would have been. 
 > > 
 > > You say you don't see harm in writing it down. That is all we are asking. 
 > > Put me in the once-bitten-twice-shy camp: I would rather have the 
 > > normative statement and not need it than need it and not have it. 
 >  
 > Your use case is to put it mildly rather exotic.  There's nothing wrong 
 > with that, but I don't think we can expect people to do anything special 
 > to ensure that it works. 
 >  
 > Unless I'm missing something, your messages look like any other locally 
 > originated one-hop messages.  You and the final recipient may know that 
 > there's history wrapped up inside it, but so long as the single signature 
 > validates and the recipients don't complain, recipient mail filters will 
 > treat it like any other single hop mail. 
 >  
 > R's, 
 > John 
 > 


_______________________________________________
Ietf-dkim mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to