Hi all, While reading through the current draft, I noticed something that surprised me.
I had assumed that the specification already required the `d=` value of the initial DKIM2 signature to be aligned not only with the RFC 5321.MailFrom domain, but also with the RFC 5322.From domain. When I went looking for that language, I realized it doesn't appear to be there. That made me wonder whether this is intentional. >From my perspective, the first DKIM2 signature establishes the root of the >trust chain. If that's the case, shouldn't it also establish the identity that >users and higher-level authentication mechanisms associate with the message, >namely the RFC 5322.From domain, rather than only the SMTP envelope identity? While thinking about this, I also realized that RFC 5322.Sender (when present) and RFC 9057.Author (when present) may deserve some consideration as well. I hadn't previously thought about those fields, but once I started looking at which identities a message can legitimately express, it seemed worth asking whether the specification should define any relationship between the initial `d=` value and those identities too. I'm not proposing specific normative text at this point. I'm mainly trying to understand whether the current wording is an intentional design choice, or whether the draft should more explicitly define which message identities the first DKIM2 signature is expected to represent. I'd be interested in hearing the working group's thoughts. Regards, Tobias
_______________________________________________ Ietf-dkim mailing list -- [email protected] To unsubscribe send an email to [email protected]
