Hi all,

One more observation from my reading of the draft.

I noticed that I couldn't find any guidance on introducing DKIM2 for messages 
originating from systems that are not DKIM2-aware.

The draft appears to assume that the trust chain starts at the originator, 
which intuitively seems like the cleaner model to me. However, I could also 
imagine deployments where the first DKIM2-capable MTA attempts to introduce an 
existing message into the DKIM2 ecosystem.

If such a deployment is not intended, I think it might be worth stating that 
explicitly. If it is intended, I would have expected the draft to discuss the 
associated trust semantics and what exactly the first DKIM2 signature is 
asserting in that situation.

I'm not advocating for introducing this capability—in fact, my expectation was 
that the trust chain should begin with the originator. I was simply surprised 
that I couldn't find any text confirming or rejecting this deployment model.

Regards,
Tobias
_______________________________________________
Ietf-dkim mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to