On Fri 18/Dec/2020 21:05:43 +0100 John R Levine wrote:
Info which is encoded in such a way that only the sender can understand rises no PII concern, IMHO.  A sender could cache sent messages and devise how to encode the corresponding filenames in DKIM selectors.  Reporting just the failed signature would leak the whole message by reference.  So what?

Now he knows which forwarded recipients are talking with his users.

Are failure reports about forwarded messages still useful? If not so much, perhaps we could deplore them.

Keeping the target of forwarded messages private needs to be addressed at emailcore as well, though. Regular bounces leak the same info.


dmarc mailing list

Reply via email to