Re: antiphishing idea

Christian Grunfeld <[email protected]>
Newsgroups gmane.ietf.asrg
Message-ID <CAFduganLWiFQSRP9uG4auEr-bXsHcKSQV=2+C2pEF4AK3QGdKw@mail.gmail.com>
2011/11/17 John Levine <[email protected]>:
>>Domains should have to publish in their DNSs the message-id (among any
>>other thing) through a TXT or A record of any legit mail sent by them.
>>The TTLs of those records can be adjusted to compensate for queued
>>mails, etc.
>
> Maybe I'm missing something, but why would you want to do this rather
> than a DKIM signature?  DKIM validates against the DNS, and protects
> the whole message.

because I can have a proper configured domain, I can properly sign my
mails but I can send you an email with From: paypal.com header !
DKIM does not protect you against this ! DKIM says that evil.com signs
correctly the email and no alarms will trigger. The average user only
see and "trust" the From: paypal.com mail header !
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.