On Mar 2, 2007, at 9:02 AM, Hallam-Baker, Phillip wrote:
I don't see how 'never sends DKIM mail' is of any value since there
is a precedence order here. The key record information takes
priority over the policy record.
So if I get mail with a valid signature I never bother to check for
the policy.
I'll wager dollars to doughnuts that when email acceptance is based
upon a DKIM signature, it will be done in conjunction with some type
of accreditation. This saves the expense of checking signatures
where validity simply does not matter.
For high profile companies that have opted to use web based
messaging, any DKIM signed email spoofing their domain creates
queries for some random key, and when that fails, then for their
policy record. Hector could be right about which will come first,
but components of a policy records can be republished with
accreditation to eliminate unnecessary traffic generated by perhaps
absorbent levels of fraud. A message that appears to be signed when
studied in the raw might mislead enough recipients, where this tactic
could become common. Not all providers will ensure these messages
are blocked.
-Doug
_______________________________________________
NOTE WELL: This list operates according to
http://mipassoc.org/dkim/ietf-list-rules.html