

Discussion summary
DKIM2 and DMARCbis are new email authentication standards gaining attention, with discussions on their impact and implementation challenges. Major providers like Gmail, iCloud, and Microsoft are involved, raising concerns about access and security.
What the discussion says
- Some see DKIM2 as a way to improve email security and reduce spam.
- Others worry it could centralize email control with big providers.
- There are concerns about setup complexity and potential new exploit vectors.
- Participants are curious about migration experiences and technical details.
“DKIM2 layering seems to fix that for mailing lists.”
“I wonder if it closes enough holes to stop using SPF.”
Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- well done
you're among the first few who have done it:
https://github.com/mjl-/mox/issues/404#issuecomment-43627498...
by meysamazad - Maybe it's time to call it CMTPby edoceo
- I wonder how this post was composed. It's full of LLM-isms, but is also pretty informative and not too fluffy - basically, higher-quality than I'm used to seeing from LLM blog posts, especially at this length. Perhaps it was composed based on a detailed human outline? Or perhaps, could this be the power of Fable?by comex
- Can someone distill this down to how it will be used by the big three email providers to make it impossible to use email except through them?by bigbuppo
- Questions:
- How much infrastructure has to be fixed before this works, and in what order?
- Can you send mail from something that doesn't have a DNS entry? How does this affect the first hop from a desktop or mobile SMTP client?
- If an spam email came via SendGrid, Constant Spammer, or MailChump, are you going to be able to tell from the header signatures?
- If your headers are correct, are you guaranteed mail bounces for un-deliverable emails?
by Animats - Missed opportunity to get rid of SPF. What I want to my DMARC policy to say: if someone is sending you an email that claims to be from my domain and it's not signed by one of the keys I have published under my domain, you should reject it, regardless where it came from.
And on the receiving side, the policy is similarly simple: if I receive any unsigned or unaligned email, I will reject it.
Edit: to clarify, I want there to be an option where I specify my DMARC policy to explicitly tell well-configured receiving servers "ignore whatever I have configured as my SPF record, only look at the signatures". There will no doubt be a long tail of mail servers where I will still need an SPF record for them to accept my mail.
Edit2: Another feature that I feel is lacking is ability to give dkim selectors a scope - e.g. this key is only valid for these particular From addresses.
- Despite what everyone said, I'm excited specifically for DKIM2. As someone that had managed a mailing list, that one is probably the hardest thing to juggle around and DKIM2 layering seems to fix that issue neatly. I hope postfix has a guide proto.by braiamp
- Aw hell. How many things do I have to set up just so that I can send e-mails from my own domain?
The effect of all this seems to be less "making e-mail secure" and more "making it so that only Google, Apple, and Microsoft can send e-mail successfully"
by qurren