You say there is nothing wrong with re-originating services and no need to do 
anything special for them. The proposed sentence says exactly that - SHOULD NOT 
treat as suspicious, evaluate on the same basis as any other Sender ADMD 
originator. It asks nothing special of anyone; it asks receivers not to apply a 
negative inference to chain absence. If the substance is agreed, writing it 
down costs nothing. If some future policy author reads Section 11.4's 
chain-of-custody language and concludes chain absence is a red flag, the 
normative text is what forecloses that. Costless insurance against a known 
failure mode.

On the long tail: Apple Hide My Email, SimpleLogin, Firefox Relay, DuckDuckGo 
Email Protection. These are not obscure operators. The category is also growing 
into DKIM2's deployment window, not retreating from it. And BCPs regularly 
address patterns that are not the majority case - nd= imaginary hops and 
donotexplode are not mainstream deployment scenarios either.

The DMARC mailing list case is the direct precedent: the WG believed the answer 
was obvious, didn't write it down, and p=reject broke lists anyway. The cost of 
BCP text when the answer is obvious is zero. The cost of its absence proved not 
to be.

William Weiner
Weiner Advanced Development LLC, maker of EMail Parrot (emparrot.com)



From: John Levine <[email protected]>
To: <[email protected]>
Cc: <[email protected]>
Date: Thu, 16 Jul 2026 13:37:22 -0600
Subject: [Ietf-dkim] Re: DKIM2 with message encryption

 > It appears that William Weiner  <[email protected]> said: 
 > >Receiver ADMDs SHOULD NOT treat a message bearing a single valid DKIM2 
 > >originator signature as suspicious solely because no prior chain is 
 > >present and the message carries threading markers (References, 
 > >In-Reply-To). Threading markers without a prior chain is the expected and 
 > >legitimate output of a re-originating intermediary (see Section 5.x). A 
 > >valid single-hop DKIM2 signature from a re-originating service should 
 > >be evaluated on the same basis as any other Sender ADMD originator 
 > >signature. 
 >  
 > I'm with Richard. From the recipient's point of view your mail is no 
 > different 
 > from any other mail that happens to be a reply to another message, so 
 > there's 
 > nothing interesting to say here. 
 >  
 > Also, re-originating services are very far out on the long tail and while 
 > there is 
 > nothing wrong with them, it's not reasonable to ask people to do anything 
 > special 
 > for them.  Fortunately, there's no need to do so. 
 >  
 > R's, 
 > John 
 >  
 > _______________________________________________
 > Ietf-dkim mailing list -- [email protected]
 > To unsubscribe send an email to [email protected]
 > 


_______________________________________________
Ietf-dkim mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to