On Wed, Aug 5, 2026 at 10:15 AM John Levine <[email protected]> wrote:
> It appears that Hannah Stern <[email protected]> said: > >Hi! > > > >The draft contains a t=s flag, described like this: > > > > s > > : Any DKIM2 signature header fields using the "i=" tag MUST have > > the same domain value on the right-hand side of the "@" in the > > "i=" tag and the value of the "d=" tag. That is, the "i=" > > domain MUST NOT be a subdomain of "d=". Use of this flag is > > > > RECOMMENDED unless subdomaining is required. > > > >However, in the DKIM2 main draft, the i= tag means something completely > >different, so this makes no sense at all? Can this paragraph be just > >removed from the draft? > > Looks like a leftover from DKIM1 and its useless i= tag which puported to > identify individual users in a domain. I agree it should go. > Sure that sounds good to me. My plan was to state that it is deprecated for DKIM2, rather than deleting the text. Indeed this text is a leftover from DKIM1 where consensus wasn't clear, but glad it's being clarified. What about deprecating "t=y" (the testing declaration domain flag) for DKIM2? Then the entire Flags section can be deprecated. We've seen issues with "t=y" for DKIM1 where domains appear to use it on what look like production keys. -Wei
_______________________________________________ Ietf-dkim mailing list -- [email protected] To unsubscribe send an email to [email protected]
