On Tue 14/Feb/2023 06:43:22 +0100 Evan Burke wrote:
On Fri, Feb 10, 2023 at 2:31 PM Michael Thomas <m...@mtcc.com> wrote:
On 2/10/23 2:10 PM, Evan Burke wrote:

The M3AAWG BCP will cover recommended header signing/oversigning policies. I'll make sure that's shared here when it's published.

Any idea when that might drop?

I'll roughly summarize the guidance here for now. [...]

Top two most effective techniques here, in terms of minimizing long-term
viability of replay, are 1) signature expiration, and 2) shorter expiration
for higher-risk accounts.


Aha, (2) implies different signing based on account. Are there other differences in the signatures, in particular of the type that can be seen by receivers (e.g. i=bullshitters@...)?


Best
Ale
--





_______________________________________________
Ietf-dkim mailing list
Ietf-dkim@ietf.org
https://www.ietf.org/mailman/listinfo/ietf-dkim

Reply via email to