MESSAGE
DATE | 2017-09-23 |
FROM | ruben safir
|
SUBJECT | Subject: [Hangout - NYLXS] DKIM set ups
|
I'm reading this text on setting up dkim
http://www.zytrax.com/books/dns/ch9/dkim.html#examples
and this paragraph has me confused and puzzled
To illustrate this process, assume that mail with an address of user-at-example.com when originated from the office is sent from, and signed by, the example.com MTA which maintains a single private/public key pair for this purpose. The example.com domain publishes the public key in its DNS in a DKIM TXT RR under the name onlyone._domainkey.example.com. The DKIM-Signature mail header from mail originating from the example.com MTA will therefore contain (among others) an s=onlyone (selector) field and a d=example.com (domain-name) field from which the receiving or validating mail server can construct the DKIM TXT RR name as defined above and authenticate the email.
Now assume further that user-at-example.com will also send mail from home via an ISP's MTA whose domain name is example.net and which publishes its DKIM public key under the name publicmail._domainkey.example.net. In this case the DKIM-Signature mail header covering mail sent from the mail address, say, user-at-example.com (and perhaps all other mail originating from this MTA) will contain an s=publicmail (selector) field and a d=example.net (domain-name) field from which, again, the receiving or validating mail server can construct the DKIM TXT RR name as defined above and authenticate the email. By default the signer will sign mail for the domain and all its subdomains - meaning that a single DKIM TXT RR can be created to cover the entire domain. Mail sent from user-at-example.com and user-at-sub.example.com can use the same selector and hence use the same key.
~~
If I understand correctly, someone sending email from an eternal MTA with a foreign email address ends up with a signature from the foreign MTA. What use is that? It is still an open relay. _______________________________________________ Hangout mailing list Hangout-at-nylxs.com http://www.nylxs.com/mailman/listinfo/hangout
|
|