4 ms·
> DKIM is trivial to bypass if you can create a TXT record with your own key This is exactly what DMARC prevents. With DMARC the alignment requirement is added
by LeonM 2y ago
> DKIM is trivial to bypass if you can create a TXT record with your own key
This is exactly what DMARC prevents. With DMARC the alignment requirement is added, so signing an email with a different domain key will no longer work.
For a DMARC pass you need DKIM alignment. DKIM alignment means that the email is correctly signed with a DKIM key that is published under the sender (rfc5322.From) domain.
- aaronmdjones 2y agoYes, and if you can get modification access to the TXT records for the sender's domain, you can compromise both DKIM and SPF. That's my point. Edit: More specifically, that it doesn't make sense to force both of them to pass when they both share a single point of failure.
- LeonM 2y agoIf your DNS is compromised it's game over anyway, because then everything is compromised. DNS is a single point of failure. You'll also be able to reroute inbound email, MITM HTTP traffic, order rogue TLS certificates, etc. etc. Saying DKIM is flawed because you can create rogue keys with DNS access is the same as saying the entire PKI is flawed because you can order certificates using DNS-01 verification.
- aaronmdjones 2y agoI didn't say DKIM was flawed. I wasn't complaining about DKIM at all. You may want to re-read the comment I was replying to. I'm well aware of the consequences of a DNS compromise. I simply said, twice, that DMARC forcing both SPF and DKIM to align and pass doesn't add anything of value; if you are capable of subverting one of them, you are almost certainly capable of subverting both of them at the same time.