[postgis-devel] DMARC/DKIM mitigation on maling lists

Regina Obe lr at pcorp.us
Wed Oct 25 14:40:15 PDT 2023


>   Some domains publish a DMARC policy that says:
>     if you get mail from my domain, then accept it if one of the
>     following is true:
>       it came direct from my outgoing mailservers (SPF)
>       my domain signed it *and the signature is valid* (DKIM)
>     otherwise, treat as spam or outright reject
> 
>   Modifying the subject is an attack on the message, cryptgraphically,
>   So is adding a footer.  These break the DKIM signature.
> 

Thanks for the clarification.  That was the piece of information I was
missing.
I guess in that vein, I can sacrifice my need to see PostGIS in the subject
line.

Thanks,
Regina



More information about the postgis-devel mailing list