On Mar 14, 2007, at 6:42 PM, Hector Santos wrote:

We are not talking about DAY 1 of the Internet here. But 35+ years, and we have enough knowledge and insight to know today that if you can recognize the creation of a potential problem, then it would be neglectful if a) you didn't bring it up and b) if you continue to pursue such a course to allow it to happen.

DKIM represents a change in how message content can be identified. Placing information at the domain helps in preventing false-positive filtering of valid messages and allows more aggressive filtering of phishing attempts. DKIM does not include any means to determine whether a transmitter is controlled by an affiliated entity, or whether there is a chance a message is part of campaign expending the signer's clout with abusive replays. Perhaps a lower false-positive rate with a means to assure email-addresses is more than good enough.

DKIM serving as a basis for white-listing also depends on who is allowed to utilize the signing-domain. Unless each person obtains their own signing-domain, DKIM signature abuse will likely preclude the general public from obtaining enhanced deliverability. : (

When everyone obtains their own signing-domain, tracking reputations will be difficult. Everyone will also be in jeopardy of having their signature besmirched by replays of perhaps innocent messages, as tolerance for abusive replays may become wickedly low.

Bad actors are obtaining millions of new domains every day. How many bad emails will it take before a signing-domain ends up on someone's do-not-accept list? This could be worse than an IP address black- hole listing, as DKIM requires the signing-domain match that of the assured email-address. Someone's email-address could easily become forfeit as a result of the abuse DKIM policy does not offer a means to control. Not even your version SSP helps with this type of problem either.

While the Internet has been around for a while, the next few years will be bringing in many changes. The only thing that remains the same is change. It seems there are many possible scenarios ignored with your policy categorizations. Bad actors are good at leveraging weaknesses that few thought would become a problem at the time. However, Edward Murphy is seldom wrong. : )

-Doug




_______________________________________________
NOTE WELL: This list operates according to http://mipassoc.org/dkim/ietf-list-rules.html

Reply via email to