On Wed, 18 Aug 2004 [EMAIL PROTECTED] wrote:

> Ehhh... DomainKeys can be trivially saved from this trivial defeat.
> Just have the sending MTA create separate envelopes for each recipient.
> Then add an X-Envelope-To: header.  Finally have the MTA sign each envelope
> independently before delivery.  The X-Envelope-To: header will be part of
> the digest.

> On the receiving side, any RCPT TO: <> X-Envelope-To: invalidates the
> DomainKey check.

This then breaks forwarding, one of the advantages of DomainKeys over
SPF.

--
David.
_______________________________________________
Visit http://www.mimedefang.org and http://www.canit.ca
MIMEDefang mailing list
[EMAIL PROTECTED]
http://lists.roaringpenguin.com/mailman/listinfo/mimedefang

Reply via email to