[ietf-dkim] Resigner Support of RFC 5617 (ADSP)

Wietse Venema wietse at porcupine.org
Mon Oct 12 07:04:17 PDT 2009


Michael Deutschmann:
> If this is indeed the official semantics of the protocol, then I would
> petition to add a "dkim=except-mlist" policy.  Which means "I sign
> everything that leaves my bailiwick, but may post to signature-breaking
> MLs."

Are you going to announce all your users mailing list subscriptions
in the policy record? If you do, that could be a privacy problem.

If you don't, then the spammer can add any mailing list header to
the message, and they can drive their truck through this hole.

	Wietse


More information about the ietf-dkim mailing list