On 14/04/2023 16:10, Jarland Donnell via mailop wrote:
Correct me if I'm wrong but isn't the trust level of ARC basically "trust me bro?" At least SRS and SPF require ownership of the domain.

Even with SRS you're still fundamentally saying "trust me bro" that what you rewrote was actually what it was. SPF kinda does require ownership but that's the thing you're breaking with the forward... What tips the balance even more towards ARC is that you're also not messing up DKIM in the process, which means you can say "trust me bro or look at this signature."

