Hi all, One more observation from my reading of the draft.
I noticed that I couldn't find any guidance on introducing DKIM2 for messages originating from systems that are not DKIM2-aware. The draft appears to assume that the trust chain starts at the originator, which intuitively seems like the cleaner model to me. However, I could also imagine deployments where the first DKIM2-capable MTA attempts to introduce an existing message into the DKIM2 ecosystem. If such a deployment is not intended, I think it might be worth stating that explicitly. If it is intended, I would have expected the draft to discuss the associated trust semantics and what exactly the first DKIM2 signature is asserting in that situation. I'm not advocating for introducing this capability—in fact, my expectation was that the trust chain should begin with the originator. I was simply surprised that I couldn't find any text confirming or rejecting this deployment model. Regards, Tobias
_______________________________________________ Ietf-dkim mailing list -- [email protected] To unsubscribe send an email to [email protected]
