After discussion with John L, it seems the best way to handle the
multiple signature issue in section 4 is to leave it as is:
Signers SHOULD NOT remove any DKIM-Signature header fields
from messages they are signing, even if they know that the
signatures cannot be verified.
eric