[ietf-dkim] DKIM Interoperability Event notes

Murray S. Kucherawy msk at sendmail.com
Thu Nov 8 14:19:44 PST 2007


On Thu, 8 Nov 2007, Hector Santos wrote:
> It is clearly a threat entry point allowing anyone to try to create a 
> DKIM signature and all they have to do is add t=y with the hope the 
> receiver will ignore all fail validations.

There was no discussion on this point.

How can an attacker add t=y to a signature?  That only exists in keys and 
policies.


More information about the ietf-dkim mailing list