I agree we need language defining the relationship between the RFC5322 From
header field identities and DKIM2 identifiers.  We should bring this up in
the IETF Vienna next week and certainly discuss it here.  Potentially these
relationships could help us define who the message "originator" is and,
subsequently, who the forwarders are.  A closely related topic is how a
DKIM2 forwarder handles a properly authenticated DKIM1 signed message i.e.
whether it should DKIM2 sign the message and how it should identify that it
is not the originator.  Some forwarders rewrite the From header, and we
should also define how to support rewriting those From headers so that it
doesn't preclude identifying the initial originator.  Having a common
"language" to communicate the states of the DKIM2 hops—whether as an
"originator" or "forwarder"—would be useful. Ultimately I hope a
specification of this is formally written up in a BCP or better yet, a
standards track document such as an update to DMARC RFC9989.
-Wei

On Wed, Jul 15, 2026 at 1:44 PM Tobias Herkula <tobias.herkula=
[email protected]> wrote:

> Hi all,
>
> While reading through the current draft, I noticed something that
> surprised me.
>
> I had assumed that the specification already required the `d=` value of
> the initial DKIM2 signature to be aligned not only with the RFC
> 5321.MailFrom domain, but also with the RFC 5322.From domain. When I went
> looking for that language, I realized it doesn't appear to be there.
>
> That made me wonder whether this is intentional.
>
> >From my perspective, the first DKIM2 signature establishes the root of
> the trust chain. If that's the case, shouldn't it also establish the
> identity that users and higher-level authentication mechanisms associate
> with the message, namely the RFC 5322.From domain, rather than only the
> SMTP envelope identity?
>
> While thinking about this, I also realized that RFC 5322.Sender (when
> present) and RFC 9057.Author (when present) may deserve some consideration
> as well. I hadn't previously thought about those fields, but once I started
> looking at which identities a message can legitimately express, it seemed
> worth asking whether the specification should define any relationship
> between the initial `d=` value and those identities too.
>
> I'm not proposing specific normative text at this point. I'm mainly trying
> to understand whether the current wording is an intentional design choice,
> or whether the draft should more explicitly define which message identities
> the first DKIM2 signature is expected to represent.
>
> I'd be interested in hearing the working group's thoughts.
>
> Regards,
> Tobias
>
> _______________________________________________
> Ietf-dkim mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
>
_______________________________________________
Ietf-dkim mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to