On Tue, 16 Aug 2005, Thomas Roessler wrote:
>
> What does "know that a message came from a designated source" mean?
>
> One interpretation is that the recipient knows that the sender sent
> this particular instance of the message to him.  To make this
> happen, one would probably want to sign
>
>    (message-id, message-hash, envelope sender, envelope recipient)
>
> tuples (maybe with RFC2822.from instead of SMTP.mailfrom)

You can't include the envelope recipient address in the signature because
it is lost when the message passes through a forwarder.

Tony.
-- 
f.a.n.finch  <[EMAIL PROTECTED]>  http://dotat.at/
BISCAY: WEST 5 OR 6 BECOMING VARIABLE 3 OR 4. SHOWERS AT FIRST. MODERATE OR
GOOD.
_______________________________________________
ietf-dkim mailing list
http://dkim.org

Reply via email to