On Mar 14, 2007, at 6:42 PM, Hector Santos wrote:
We are not talking about DAY 1 of the Internet here. But 35+
years, and we have enough knowledge and insight to know today that
if you can recognize the creation of a potential problem, then it
would be neglectful if a) you didn't bring it up and b) if you
continue to pursue such a course to allow it to happen.
DKIM represents a change in how message content can be identified.
Placing information at the domain helps in preventing false-positive
filtering of valid messages and allows more aggressive filtering of
phishing attempts. DKIM does not include any means to determine
whether a transmitter is controlled by an affiliated entity, or
whether there is a chance a message is part of campaign expending the
signer's clout with abusive replays. Perhaps a lower false-positive
rate with a means to assure email-addresses is more than good enough.
DKIM serving as a basis for white-listing also depends on who is
allowed to utilize the signing-domain. Unless each person obtains
their own signing-domain, DKIM signature abuse will likely preclude
the general public from obtaining enhanced deliverability. : (
When everyone obtains their own signing-domain, tracking reputations
will be difficult. Everyone will also be in jeopardy of having their
signature besmirched by replays of perhaps innocent messages, as
tolerance for abusive replays may become wickedly low.
Bad actors are obtaining millions of new domains every day. How many
bad emails will it take before a signing-domain ends up on someone's
do-not-accept list? This could be worse than an IP address black-
hole listing, as DKIM requires the signing-domain match that of the
assured email-address. Someone's email-address could easily become
forfeit as a result of the abuse DKIM policy does not offer a means
to control. Not even your version SSP helps with this type of
problem either.
While the Internet has been around for a while, the next few years
will be bringing in many changes. The only thing that remains the
same is change. It seems there are many possible scenarios ignored
with your policy categorizations. Bad actors are good at leveraging
weaknesses that few thought would become a problem at the time.
However, Edward Murphy is seldom wrong. : )
-Doug
_______________________________________________
NOTE WELL: This list operates according to
http://mipassoc.org/dkim/ietf-list-rules.html