[ietf-dkim] Not exactly not a threat analysis

Dave Crocker dhc at dcrocker.net
Wed Aug 24 08:46:18 PDT 2005


On Wed, 24 Aug 2005 08:39:41 -0700, Michael Thomas wrote:
>  Who knows? I mean, if mail eventually needs to be
>  signed before it's accepted by the masses, they may
>  well be forced to sign -- or find some other transport
>  vehicle.

I think that the history of adoption of SPF by spammers demonstrates nicely that 
the mere act of associating a confirmable identity is not enough.  So the mere 
act of signing should not be a criterion for acceptance of the mail.

The required additional step is some basis for assessing that identity.


  d/
  ---
  Dave Crocker
  Brandenburg InternetWorking
  +1.408.246.8253
  dcrocker  a t ...
  WE'VE MOVED to:  www.bbiw.net





More information about the ietf-dkim mailing list