Qmail
[Top] [All Lists]

Re: Broken DomainKey .. or dead project?

To: qmail@list.cr.yp.to
Subject: Re: Broken DomainKey .. or dead project?
From: Kyle Wheeler <kyle-qmail@memoryhole.net>
Date: Wed, 4 Apr 2007 14:24:52 -0600
Comment: DomainKeys? See http://antispam.yahoo.com/domainkeys
Delivered-to: sp-com-lists@consult.net
Delivered-to: gmail-qmail@securepoint.com
Delivered-to: sp.com.list@gmail.com
Delivered-to: mailing list qmail@list.cr.yp.to
Domainkey-signature: a=rsa-sha1; q=dns; c=nofws; s=default; d=memoryhole.net; b=iWFdRShHiF/EKUejecLmPJ4gVbwWcULLLHEblWchsCI4GlXPgmvTHi4xZ/5qHb1qKFal+vThvZVx8LC42WRQSWwmEAhHpJ8V+nwDtiOeg7anv9vz2jD+XzyQfKKn2sa0wOvw3YFD4vRD5BPwa1FRGtTdW5CpXTDCFfPYBjPvxEw= ;
Domainkey-status: good
In-reply-to: <20070404200344.GA20446@discworld.dyndns.org>
Mail-followup-to: qmail@list.cr.yp.to
Mailing-list: contact qmail-help@list.cr.yp.to; run by ezmlm
References: <b86db13f0704011331m4135c427vc934ced0d8b64120@mail.gmail.com> <20070401205313.GA5988@discworld.dyndns.org> <b86db13f0704011429x17f3e0b1w903861f725380af5@mail.gmail.com> <20070401225748.GA6359@discworld.dyndns.org> <1175514940.31108.92.camel@castor.taos-it.nl> <b86db13f0704041207p6b6c548ai617ff192c7d27414@mail.gmail.com> <p06240603c239aa94b54f@[128.163.18.106]> <20070404200344.GA20446@discworld.dyndns.org>
User-agent: Mutt/1.5.14 (2007-04-03)
On Wednesday, April  4 at 02:03 PM, quoth Charles Cazabon:
Matt Simpson <net-qmlist@jmatt.net> wrote:
[...]
There are still some issues with qmail-dk. One that I recently encountered was not being able to sign bounce messages. I still haven't resolved that one.

Not being up on DK, I could be wrong -- but wouldn't it be impossible for any DK implementation? A bounce message has a null return path, so there's no domain to look up in DNS to get the right keys...

The DK header itself tells you what domain to look up. It doesn't have to be the same as the return address, either. Thus, when forwarding messages through your server, you can still sign them (certifying that they went through your server). A message can end up with multiple DK signatures that way, but that's not a bad thing. If anything, it means there's more verifiable information about the path of the email.

~Kyle
--
'We hold these truths to be self-evident,' they said, 'that all men are created equal.' Strange as it may seem, that was the first time in history that anyone had ever bothered to write that down. Decisions are made by those who show up.
                                         -- Jed Bartlet, The West Wing

Attachment: pgplToqC7zupF.pgp
Description: PGP signature

<Prev in Thread] Current Thread [Next in Thread>