[ietf-dkim] Re: Single Organization TXT Lookup with Multiple TXT Records Result

Damon deepvoice at gmail.com
Mon Jun 4 08:12:47 PDT 2007


> What I am suggesting is a bit different.  As this label must have a
> prefix, why not allow the prefix to associate with another domain via a
> hash?  Check the existence of an MX record when no policy record is
> found.  When policy record lookup fails and the MX record exists (we are
> at two transactions), a third lookup could be for
> _dkim-all.<email-address-domain> to determine whether a lack of an
> association is acceptable.
>
> This approach represents the same number of transactions as suggested by
> Phillip, but also provides a means to curtail a replay-abuse and
> broken-signature bounce problem.  Doing this now ensures at most one
> additional transaction occurs.  This seems well worth it.
>

 Doug,

 Interesting idea. Can you provide an example of how this would work IRL?
I am confused about the "hash".

Regards,
Damon


More information about the ietf-dkim mailing list