[ietf-dkim] Authorizing List Domains

Murray S. Kucherawy msk at cloudmark.com
Mon Sep 27 15:13:28 PDT 2010


> -----Original Message-----
> From: ietf-dkim-bounces at mipassoc.org [mailto:ietf-dkim-bounces at mipassoc.org] On Behalf Of Douglas Otis
> Sent: Monday, September 27, 2010 3:02 PM
> To: ietf-dkim at mipassoc.org
> Subject: Re: [ietf-dkim] Authorizing List Domains
> 
> You have placed TPA information in a domain not below
> "_domainkey.<signing-domain>".  This increases the response size by 11
> bytes with a trade-off of making delegations to signing mail providers
> more difficult.  I am open to either approach, however only DKIM makes
> this scheme practical.

How does it make something more difficult?

> At the same time, unless authorizations can defend against
> likely abuse, that too would render efforts unusable.  The additional
> information also benefits the recipient when it simplifies their
> process and increases the number of messages being properly marked for
> rejection.

I don't really want to conduct an experiment that includes myriad optional policy specifications without some operational data to suggest they stand a chance of adoption.  Simpler is better.




More information about the ietf-dkim mailing list