[postgis-devel] DMARC/DKIM mitigation on maling lists

Sandro Santilli strk at kbt.io
Thu Oct 26 00:48:55 PDT 2023


On Wed, Oct 25, 2023 at 05:40:15PM -0400, Regina Obe via postgis-devel wrote:
> >   Some domains publish a DMARC policy that says:
> >     if you get mail from my domain, then accept it if one of the
> >     following is true:
> >       it came direct from my outgoing mailservers (SPF)
> >       my domain signed it *and the signature is valid* (DKIM)
> >     otherwise, treat as spam or outright reject
> > 
> >   Modifying the subject is an attack on the message, cryptgraphically,
> >   So is adding a footer.  These break the DKIM signature.
> > 
> 
> Thanks for the clarification.  That was the piece of information I was
> missing.
> I guess in that vein, I can sacrifice my need to see PostGIS in the subject
> line.

I've filed an OSGeo ticket placeholder to come to a final recommendation for
OSGeo mailing list owners about how to configure mailman:

  https://trac.osgeo.org/osgeo/ticket/3011

--strk;


More information about the postgis-devel mailing list