3 ms·
If your DNS is compromised it's game over anyway, because then everything is compromised. DNS is a single point of failure. You'll also be able to reroute inbou
by LeonM 2y ago
If your DNS is compromised it's game over anyway, because then everything is compromised. DNS is a single point of failure. You'll also be able to reroute inbound email, MITM HTTP traffic, order rogue TLS certificates, etc. etc.
Saying DKIM is flawed because you can create rogue keys with DNS access is the same as saying the entire PKI is flawed because you can order certificates using DNS-01 verification.
- aaronmdjones 2y agoI didn't say DKIM was flawed. I wasn't complaining about DKIM at all. You may want to re-read the comment I was replying to. I'm well aware of the consequences of a DNS compromise. I simply said, twice, that DMARC forcing both SPF and DKIM to align and pass doesn't add anything of value; if you are capable of subverting one of them, you are almost certainly capable of subverting both of them at the same time.