40 likes | 52 Views
DKIM Extensions. Phillip Hallam-Baker. X.509v3 Cert Pointer. Extension to key record Associates a certificate with the key record Must bind to same key Domain Validated Cert Protection against DNS/BGP attack EV Certificate Establish accountability (not spammer)
E N D
DKIM Extensions Phillip Hallam-Baker
X.509v3 Cert Pointer • Extension to key record • Associates a certificate with the key record • Must bind to same key • Domain Validated Cert • Protection against DNS/BGP attack • EV Certificate • Establish accountability (not spammer) • Allows additional attributes to be specified • E.g. PKIX Logotype extension
NOMAIL Policy Extension • I don’t do email so checking DKIM policy is not relevant • Simple statement for parked domains
NULL Key • For large enterprises with many addresses • Adding DKIM signature may not be possible • Adding a static header line is usually possible • NULL key with sender restriction • Allows ‘hole’ to be created in policy • Does not negate policy as a whole