On Monday 10 December 2007 09:57, Eliot Lear wrote:
> Dave,
>
> >      The underlying problem is with coupling the From field to the
> > DKIM signature.  At most, the Sender value should be used.
>
> It would indeed be nice to use the Sender field, but I would be
> concerned about the Sender field not at least matching one of the
> domains of one of the RFC2822.From lines, lest someone attempt to bypass
> the tests by inserting a Sender.  But then we need an extra rule in the
> state machine.  Perhaps it is better to explicitly deprecate multiple
> From lines?  As UIs have developed they really don't index well against
> multiple From lines anyway.
>
We went through all this at the time the decision to use first From was made.  
No new information has been provided to warrant reconsideration.  I'd suggest 
just mark the issue a duplicate and move on.

Scott K
_______________________________________________
NOTE WELL: This list operates according to 
http://mipassoc.org/dkim/ietf-list-rules.html

Reply via email to