Re: [Ietf-dkim] Misuse of antiforgery protocols

2022-12-15 Thread Grant Taylor
On 12/14/22 7:21 PM, Evan Burke wrote: Generally: x= is automatic and will usually be faster, and requires no engineering effort to build out the key management service, and no ongoing operational/maintenance/infrastructure costs. I did say "possibly a LOT, more complex". Looks like a lot

Re: [Ietf-dkim] Misuse of antiforgery protocols

2022-12-15 Thread Alessandro Vesely
On Thu 15/Dec/2022 00:46:42 +0100 Jim Fenton wrote: On 13 Dec 2022, at 17:00, Michael Thomas wrote: Which brings up a question: even though they pass on DKIM they should fail on SPF, right? For transactional email that seems like a big old red flag, right? Some people use receive-side

Re: [Ietf-dkim] Misuse of antiforgery protocols

2022-12-15 Thread Laura Atkins
> On 15 Dec 2022, at 00:46, Grant Taylor > wrote: > > On 12/14/22 11:10 AM, Evan Burke wrote: >> It doesn't. Most of the accounts are caught before sending. All it takes is >> one to slip through the anti-spam detections and then go send millions of >> replay spam messages or more - even if