3 ms·
Just to be clear, the post is about minimizing the limited non-repudiation properties that DKIM is currently giving email as a side effect. > I would consider
by ryan-c 6y ago
Just to be clear, the post is about minimizing the limited non-repudiation properties that DKIM is currently giving email as a side effect.
> I would consider it a very poor idea to have a set of automatic scripts messing around with the MX records or DKIM records on the domain zonefiles on my set of authoritative-only nameservers. Those things aren't meant to change often.
These are entirely reasonable concerns, and I have a dedicated zone for _domainkey.ryanc.org set up to manage that risk.
> There is no need to start doing things that require you to set very low TTLs on your domain zonefiles and then blindly trust that every caching DNS resolver out there on the internet will respect that (breaking news: they won't! it will break mail delivery in new and amazing ways!)
Also true, and it's why despite the 5 second TTL I wait days between revoking the selector and publishing the private parameters.
- nullc 6y agoWere you aware of https://as397444.net/dkim/ https://as397444.net/dkim/ e.g. https://as397444.net/dkim/as397444.net/ https://as397444.net/dkim/as397444.net/ ? ( He writes a notice in the headers https://twitter.com/as397444/status/1291178153084428288 https://twitter.com/as397444/status/1291178153084428288 ) Also this thread: https://www.mail-archive.com/mailop@mailop.org/msg10962.html https://www.mail-archive.com/mailop@mailop.org/msg10962.html
- ryan-c 6y agoI was not, thank you for the link. I've been running my key disclosures for over three years, Matthew Green's Tweet about it motivated me to write it up.