<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.moccia-dkim2-deployment-profile" target="https://datatracker.ietf.org/doc/html/draft-moccia-dkim2-deployment-profile-07">
   <front>
      <title>A Deployment Profile for DKIM2 via Milter Interface</title>
      <author initials="V." surname="Moccia" fullname="Vittorio Moccia">
         <organization>ITB.it</organization>
      </author>
      <date month="August" day="3" year="2026" />
      <abstract>
	 <t>   This document defines a deployment profile for DomainKeys Identified
   Mail v2 (DKIM2) that is implementable via the existing milter
   interface without modifications to Mail Transfer Agent (MTA) core
   software.  It identifies a mandatory core profile (DKIM2-core)
   covering envelope binding, chain of custody, header accountability,
   replay prevention and DSN authentication and an optional extended
   profile (DKIM2-extended) covering body recipes and Message-Instance
   headers.  The separation is motivated by deployment realism: the core
   profile addresses the primary threat models identified in the DKIM2
   motivation document and is deployable incrementally across
   heterogeneous infrastructure, including small operators, universities
   and research institutions, using the same milter-based deployment
   model that has proven effective for DKIM1 and ARC.

   The intent of this document is not to obstruct DKIM2 but to make it
   deployable.  DKIM2-core can be deployed incrementally across the
   heterogeneous ecosystem in a short timeframe.  DKIM2-extended
   requires significantly longer implementation cycles and may not be
   deployable in jurisdictions with stricter privacy requirements.  Both
   profiles are part of DKIM2 - the separation serves adoption, not
   opposition.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-moccia-dkim2-deployment-profile-07" />
   
</reference>
