Re: DKIM absence

2023-05-03 Thread Jared Hall
On 5/2/2023 1:02 PM, Bill Cole wrote: That is a terrible idea. There are perfectly good reasons for a domain to only sign some mail. Justifying a +3 score on something which is only wrong *IN YOUR HEAD* is hard. ADSP and DMARC both exist apart from DKIM. It is an entirely valid choice to NO

Re: DKIM absence

2023-05-02 Thread Benny Pedersen
Matus UHLAR - fantomas skrev den 2023-05-02 19:25: Greg Troxel skrev den 2023-05-02 18:29: DKIM_MISSING Domain has DKIM records but message has no DKIM signature On 02.05.23 18:59, Benny Pedersen wrote: there is no _domainkeys in dns sorry, it's _domainkey.example.com example.com have rfc

Re: DKIM absence

2023-05-02 Thread Matus UHLAR - fantomas
Greg Troxel skrev den 2023-05-02 18:29: DKIM_MISSINGDomain has DKIM records but message has no DKIM signature On 02.05.23 18:59, Benny Pedersen wrote: there is no _domainkeys in dns sorry, it's _domainkey.example.com with maybe +3 to start, as a sort-of-soft-impliced-DMARC. yes _dmar

Re: DKIM absence

2023-05-02 Thread Bill Cole
On 2023-05-02 at 12:29:53 UTC-0400 (Tue, 02 May 2023 12:29:53 -0400) Greg Troxel is rumored to have said: Matus UHLAR - fantomas writes: On 02.05.23 08:37, Thomas Johnson wrote: If there’s no dkim signature, you can’t check for dkim records in dns. The selector for a dkim signature is arb

Re: DKIM absence

2023-05-02 Thread Benny Pedersen
Greg Troxel skrev den 2023-05-02 18:29: DKIM_MISSINGDomain has DKIM records but message has no DKIM signature no there is no _domainkeys in dns with maybe +3 to start, as a sort-of-soft-impliced-DMARC. yes _dmarc is in dns (surely this is doable in a plugin; it's not conceptually ha

Re: DKIM absence

2023-05-02 Thread Greg Troxel
Matus UHLAR - fantomas writes: > On 02.05.23 08:37, Thomas Johnson wrote: >> If there’s no dkim signature, you can’t check for dkim records in >> dns. The selector for a dkim signature is arbitrary - there’s no >> one dns lookup you can do to see all possible dkim records for a >> domain. > > a

Re: DKIM absence

2023-05-02 Thread Greg Troxel
> Right, because you need to grovel out the selector from the > DKIM-Signature line. Groan. > > That you can't mark a domain as requiring DKIM at the top-level seems > to be a design flaw in the protocol. Yes, but I think the way that is fixed is spelled DMARC.

Re: DKIM absence

2023-05-02 Thread Matus UHLAR - fantomas
On May 2, 2023, at 8:27 AM, Philip Prindeville wrote: Is there a way to add scoring that says, "If the sending domain has DKIM records, but there's no DKIM signature on this message, then attach a high score to it?" We seem to attach negative scores when DKIM is present and valid, but what

Re: DKIM absence

2023-05-02 Thread Philip Prindeville
> On May 2, 2023, at 9:37 AM, Thomas Johnson wrote: > > >> On May 2, 2023, at 8:27 AM, Philip Prindeville >> wrote: >> >> Is there a way to add scoring that says, "If the sending domain has DKIM >> records, but there's no DKIM signature on this message, then attach a high >> score to it

Re: DKIM absence

2023-05-02 Thread Thomas Johnson
> On May 2, 2023, at 8:27 AM, Philip Prindeville > wrote: > > Is there a way to add scoring that says, "If the sending domain has DKIM > records, but there's no DKIM signature on this message, then attach a high > score to it?" > > We seem to attach negative scores when DKIM is present and

Re: DKIM absence

2023-05-02 Thread Benny Pedersen
Philip Prindeville skrev den 2023-05-02 17:26: Is there a way to add scoring that says, "If the sending domain has DKIM records, but there's no DKIM signature on this message, then attach a high score to it?" We seem to attach negative scores when DKIM is present and valid, but what about the op