>> The i= field doesn't do that.  DKIM doesn't identify individuals, only
>> domains.

> The spec says that it *does* identify a user.

It says that i= is the "user or agent on behalf of which this message is
signed".  It gives the example of an agent that's a mailing list, and
we've seen all sorts of other things that people put into i=.

It's certainly true the i= might identify a user, but it's equally true 
that it might identify a piece of software, or a 'bot that cracked 
someone's CAPTCHA, and without extra info external to DKIM there's no way 
a receiver or verifier can tell which of those it was really intended to 
be.

So, really, DKIM doesn't identify individuals.

R's,
John
_______________________________________________
NOTE WELL: This list operates according to 
http://mipassoc.org/dkim/ietf-list-rules.html

Reply via email to