[{"author": "Andrew Newton", "text": "<p>Now, yes</p>", "time": "2026-05-27T20:03:39.000Z"}, {"author": "Laura A", "text": "<p>yes</p>", "time": "2026-05-27T20:03:39.000Z"}, {"author": "Al Iverson", "text": "<p>Can hear you now!</p>", "time": "2026-05-27T20:03:39.000Z"}, {"author": "Alex Brotman", "text": "<p>Yes</p>", "time": "2026-05-27T20:03:40.000Z"}, {"author": "Richard Clayton", "text": "<p>yes</p>", "time": "2026-05-27T20:03:40.000Z"}, {"author": "Pete Resnick", "text": "<p>I've got no audio. Let me restart.</p>", "time": "2026-05-27T20:05:26.000Z"}, {"author": "Pete Resnick", "text": "<p>Parallel processing does not make for the best notetaking. Can others come into the notes and help? <a href=\"https://notes.ietf.org/notes-ietf-interim-2026-dkim-03-dkim\">https://notes.ietf.org/notes-ietf-interim-2026-dkim-03-dkim</a></p>", "time": "2026-05-27T20:14:11.000Z"}, {"author": "Pete Resnick", "text": "<p>Did I miss one?</p>", "time": "2026-05-27T20:14:27.000Z"}, {"author": "John Levine", "text": "<p>We should exclude Delivered-To:, which is in effect a trace header and Postfix adds it</p>", "time": "2026-05-27T20:15:11.000Z"}, {"author": "Murray Kucherawy", "text": "<p>I'm partial to not making any reference to trace fields as a decision about sign/not-sign, or to a registry in general.  That requires software to be current on what things are trace fields.</p>", "time": "2026-05-27T20:16:55.000Z"}, {"author": "Murray Kucherawy", "text": "<p>The problem with Bron's argument is that he's out of focus.</p>", "time": "2026-05-27T20:20:32.000Z"}, {"author": "Bron Gondwana", "text": "<p>My wifi is so bad I have resorted to 5G</p>", "time": "2026-05-27T20:21:02.000Z"}, {"author": "Bron Gondwana", "text": "<p>The problem with dkim2 is that the signed list is not specified, so both ends MUST agree on what gets signed</p>", "time": "2026-05-27T20:22:31.000Z"}, {"author": "John Levine", "text": "<p>DKIM1 puts an explicit list of header names in the signature. Is that still true?</p>", "time": "2026-05-27T20:22:35.000Z"}, {"author": "Bron Gondwana", "text": "<p>this has been discussed mutliple times</p>", "time": "2026-05-27T20:22:38.000Z"}, {"author": "Andrew Newton", "text": "<p>If I am getting the notes wrong.... please correct</p>", "time": "2026-05-27T20:24:18.000Z"}, {"author": "Bron Gondwana", "text": "<p>Good point, I shall go join</p>", "time": "2026-05-27T20:25:14.000Z"}, {"author": "Murray Kucherawy", "text": "<p>Thanks, Andy.</p>", "time": "2026-05-27T20:25:16.000Z"}, {"author": "Murray Kucherawy", "text": "<p>And Bron.</p>", "time": "2026-05-27T20:25:20.000Z"}, {"author": "Bron Gondwana", "text": "<p>I don't think it's needed BUT I do think we need to have a solution just in case</p>", "time": "2026-05-27T20:26:55.000Z"}, {"author": "Bron Gondwana", "text": "<p>and we have one</p>", "time": "2026-05-27T20:27:00.000Z"}, {"author": "Steve Atkins", "text": "<p>And that solution can be entirely outside the scope of DKIM2. It's Just Another Header.</p>", "time": "2026-05-27T20:27:25.000Z"}, {"author": "Bron Gondwana", "text": "<p>Just wait until you hear my idea for signing MIME parts</p>", "time": "2026-05-27T20:31:13.000Z"}, {"author": "Bron Gondwana", "text": "<p>it'll be Just Another Header ;p</p>", "time": "2026-05-27T20:31:29.000Z"}, {"author": "Laura A", "text": "<p>And just use DMARC reporting for unsigned messages?</p>", "time": "2026-05-27T20:33:31.000Z"}, {"author": "Murray Kucherawy", "text": "<p>Laura: That's what I understood, yes.</p>", "time": "2026-05-27T20:33:45.000Z"}, {"author": "John Levine", "text": "<p>What replaces DMARC p=whatever?</p>", "time": "2026-05-27T20:34:17.000Z"}, {"author": "John Levine", "text": "<p>what if it's signed but not by the From: domain?</p>", "time": "2026-05-27T20:34:45.000Z"}, {"author": "Laura A", "text": "<p>So no reporting for messages that pass? That's removing a use case that is valuable (ie, you're trying to figure out who is sending mail out of a large organization).</p>", "time": "2026-05-27T20:34:57.000Z"}, {"author": "Bron Gondwana", "text": "<p>Yes, we need to handle a \"From address changed\".</p>", "time": "2026-05-27T20:35:03.000Z"}, {"author": "Bron Gondwana", "text": "<p>@Laura reporting for messages that pass can be requested in-band</p>", "time": "2026-05-27T20:35:12.000Z"}, {"author": "John Levine", "text": "<p>I'd just say DKIM2 sits under DMARC just like DKIM1 does</p>", "time": "2026-05-27T20:35:24.000Z"}, {"author": "Al Iverson", "text": "<p>I think DKIM2 should sit under DMARC like DKIM1 does.</p>", "time": "2026-05-27T20:35:41.000Z"}, {"author": "John Levine", "text": "<p>give or take some way to fudge From: changes</p>", "time": "2026-05-27T20:35:43.000Z"}, {"author": "Laura A", "text": "<p>Right, but that doesn't go back to a central email governance issue.</p>", "time": "2026-05-27T20:35:47.000Z"}, {"author": "Bron Gondwana", "text": "<p>I guess if you're a large org where some people will send signed messages WITHOUT adding the request</p>", "time": "2026-05-27T20:35:52.000Z"}, {"author": "Bron Gondwana", "text": "<p>yeah</p>", "time": "2026-05-27T20:36:01.000Z"}, {"author": "Al Iverson", "text": "<p>Agreed - org level reporting is important and valuable.</p>", "time": "2026-05-27T20:36:17.000Z"}, {"author": "Bron Gondwana", "text": "<p>OK I need to re-think my beliefs!  Thanks</p>", "time": "2026-05-27T20:36:46.000Z"}, {"author": "Laura A", "text": "<p>In band is useful, but doesn't meet the use case.</p>", "time": "2026-05-27T20:37:07.000Z"}, {"author": "Murray Kucherawy", "text": "<p>Anyone want to take some of that to the mic?</p>", "time": "2026-05-27T20:37:11.000Z"}, {"author": "Andrew Newton", "text": "<p>distractions... can someone capture Richard</p>", "time": "2026-05-27T20:38:00.000Z"}, {"author": "Murray Kucherawy", "text": "<p>Did he get loose again?</p>", "time": "2026-05-27T20:39:55.000Z"}, {"author": "John Levine", "text": "<p>My friends at arXiv have exactly that problem, not knowing all the places that are sending mail</p>", "time": "2026-05-27T20:40:15.000Z"}, {"author": "John Levine", "text": "<p>they're in Google Cloud, it's all supposed to go through the main server, but ...</p>", "time": "2026-05-27T20:40:29.000Z"}, {"author": "Alex Brotman", "text": "<p>That does assume that the newly created third-level domain doesn't override the OrgDom DMARC, and send the reports elsewhere.</p>", "time": "2026-05-27T20:41:43.000Z"}, {"author": "Bron Gondwana", "text": "<p>There's \"deliberate misbehaviour\", that's a whole different challenge!</p>", "time": "2026-05-27T20:42:26.000Z"}, {"author": "Steve Atkins", "text": "<p>They're doing that with the \"permission\" of the DNS admins of the second level domain.</p>", "time": "2026-05-27T20:42:30.000Z"}, {"author": "Alex Brotman", "text": "<p>I get that, but sometimes that marketing guru just does what the ESP tells them to do ..</p>", "time": "2026-05-27T20:43:02.000Z"}, {"author": "Richard Clayton", "text": "<p>you can specify SPF values which count for SPF and do not count for DMARC ... just put in the correct syntax !</p>", "time": "2026-05-27T20:43:15.000Z"}, {"author": "Laura A", "text": "<p>For my use case, it's the original sending domain.</p>", "time": "2026-05-27T20:45:22.000Z"}, {"author": "Laura A", "text": "<p>ah. right.</p>", "time": "2026-05-27T20:45:35.000Z"}, {"author": "Laura A", "text": "<p>yeah, I need to think about that.</p>", "time": "2026-05-27T20:45:49.000Z"}, {"author": "Todd Herr", "text": "<p>The best way to not use SPF for the Return-Path domain of a message in a DMARC context is to not publish an SPF record for the Return-Path domain</p>", "time": "2026-05-27T20:47:27.000Z"}, {"author": "Bron Gondwana", "text": "<p>Richard: I agree with you here.  We do need that flag.</p>", "time": "2026-05-27T20:47:53.000Z"}, {"author": "Laura A", "text": "<p>Agree about the flag.</p>", "time": "2026-05-27T20:48:04.000Z"}, {"author": "Alex Brotman", "text": "<p>Yes</p>", "time": "2026-05-27T20:48:28.000Z"}, {"author": "Laura A", "text": "<p>yes</p>", "time": "2026-05-27T20:48:30.000Z"}, {"author": "John Levine", "text": "<p>yes, we don't know enough yet</p>", "time": "2026-05-27T20:48:33.000Z"}, {"author": "Todd Herr", "text": "<p>Current text in RFC9989: \"A Domain Owner can choose not to have some underlying authentication mechanisms apply to DMARC evaluation of its Author Domain(s). For example, if a Domain Owner only wants to use DKIM as the underlying authentication mechanism, then the Domain Owner does not publish an SPF record that can produce Identifier Alignment between an SPF-Authenticated Identifier and the Author Domain.\"</p>", "time": "2026-05-27T20:48:33.000Z"}, {"author": "Steve Atkins", "text": "<p>Yes.</p>", "time": "2026-05-27T20:48:37.000Z"}, {"author": "Allen Robinson", "text": "<p>The part hashes thing is so that a part doesn't have to be in Message-Instance when it is being removed. You can't unwind in that case.</p>", "time": "2026-05-27T20:51:39.000Z"}, {"author": "Allen Robinson", "text": "<p>Another case: security device associated with a well-intentioned alumni forwarder</p>", "time": "2026-05-27T20:54:38.000Z"}, {"author": "Pete Resnick", "text": "<p>I believe Richard's characterizations of \"old\" and \"modern\" here are not reasonable.</p>", "time": "2026-05-27T20:56:06.000Z"}, {"author": "Barry Leiba", "text": "<p>We need to be more terse in our speeches.</p>", "time": "2026-05-27T20:56:28.000Z"}, {"author": "Richard Clayton", "text": "<p>why would I want to receive a message that used to have a virus attached at all ?</p>", "time": "2026-05-27T20:59:31.000Z"}, {"author": "Bron Gondwana", "text": "<p>It might not have been a virus</p>", "time": "2026-05-27T20:59:44.000Z"}, {"author": "Steve Atkins", "text": "<p>(I keep putting my hand up, and then Pete says what I was going to, but better)</p>", "time": "2026-05-27T21:01:01.000Z"}, {"author": "Andrew Newton", "text": "<p>bron you dropped out</p>", "time": "2026-05-27T21:01:03.000Z"}, {"author": "Murray Kucherawy", "text": "<p>Stop it, Pete.</p>", "time": "2026-05-27T21:01:12.000Z"}, {"author": "Al Iverson", "text": "<p>\"what do you mean my valuable message wasn't delivered\"</p>", "time": "2026-05-27T21:01:26.000Z"}, {"author": "Bron Gondwana", "text": "<p>sorry; I was saying \"so long as everyone else accurately describes what they did, you can get back to the original message sans the damage\".  Saying \"I chopped N lines here\" allows you to fill those lines with lorem ipsum</p>", "time": "2026-05-27T21:02:29.000Z"}, {"author": "Allen Robinson", "text": "<p>That signature won't validate</p>", "time": "2026-05-27T21:03:02.000Z"}, {"author": "Murray Kucherawy", "text": "<p>Right.</p>", "time": "2026-05-27T21:03:06.000Z"}, {"author": "Andrew Newton", "text": "<p>sorry... I am not groking this for the minutes</p>", "time": "2026-05-27T21:03:37.000Z"}, {"author": "Richard Clayton", "text": "<p>steve is correct</p>", "time": "2026-05-27T21:04:11.000Z"}, {"author": "John Levine", "text": "<p>@steve agreed, the part stuff has to be end to end</p>", "time": "2026-05-27T21:04:22.000Z"}, {"author": "Bron Gondwana", "text": "<p>yes, original author needs to hash the mime parts; OR - anyone else can, so long as you can undo back to them.</p>", "time": "2026-05-27T21:04:54.000Z"}, {"author": "Richard Clayton", "text": "<p>if people didn't regularly have 20 attachments then it might make sense ... but the headers are enormous</p>", "time": "2026-05-27T21:04:59.000Z"}, {"author": "Murray Kucherawy", "text": "<p>Andy: The theory is that you can remove a MIME part but know its hash, and then still validate the rest of the message is unmodified since the original even though you can't restore that part.</p>", "time": "2026-05-27T21:05:22.000Z"}, {"author": "Murray Kucherawy", "text": "<p>Steve: Is that a new hand</p>", "time": "2026-05-27T21:06:12.000Z"}, {"author": "Murray Kucherawy", "text": "<p>?</p>", "time": "2026-05-27T21:06:15.000Z"}, {"author": "Al Iverson", "text": "<p>I think Steve's point is a great one, feels like we should run screaming in the other direction away from a use case that requires decoding mime complexity.</p>", "time": "2026-05-27T21:06:43.000Z"}, {"author": "Murray Kucherawy", "text": "<p>+1, they're a pain to write and test against the universe of implementations.</p>", "time": "2026-05-27T21:07:20.000Z"}, {"author": "Bron Gondwana", "text": "<p>I just want to advocate for redaction-recipe rather than \"no change at all\" recipe, and then that leaves this solveable</p>", "time": "2026-05-27T21:07:36.000Z"}, {"author": "Trent Adams", "text": "<p>I'd say it's worth another interim meeting</p>", "time": "2026-05-27T21:08:14.000Z"}, {"author": "Andrew Newton", "text": "<p>you can always cancel them</p>", "time": "2026-05-27T21:08:22.000Z"}, {"author": "Bron Gondwana", "text": "<p>The week after M3AAWG seems right to me, that's just under 3 weeks from today</p>", "time": "2026-05-27T21:09:29.000Z"}, {"author": "Bron Gondwana", "text": "<p>but the week after that would work too</p>", "time": "2026-05-27T21:09:40.000Z"}, {"author": "Bron Gondwana", "text": "<p>June 17 or 24</p>", "time": "2026-05-27T21:10:06.000Z"}, {"author": "Pete Resnick", "text": "<p>ack. Murray and I will check our calendars.</p>", "time": "2026-05-27T21:10:21.000Z"}, {"author": "Alex Brotman", "text": "<p>Do we want to use the the week after M3 as a recap from things discussed at M3?</p>", "time": "2026-05-27T21:10:39.000Z"}, {"author": "Andrew Newton", "text": "<p>I believe the 2 week rule is strictly for in-person interims. But people get upset about that rule being broken for virtual interims</p>", "time": "2026-05-27T21:10:47.000Z"}, {"author": "Al Iverson", "text": "<p>Eager for Brian G's thoughts on this -- bulk sender/ESP seems to be the primary use case.</p>", "time": "2026-05-27T21:13:33.000Z"}, {"author": "John Levine", "text": "<p>week after M3 works for us who will be at ICANN instead</p>", "time": "2026-05-27T21:14:58.000Z"}, {"author": "Allen Robinson", "text": "<p>The DSN should have the message being returned, so your signature should be the top one. Pretty easy check.</p>", "time": "2026-05-27T21:24:29.000Z"}, {"author": "Bron Gondwana", "text": "<p>Agree with Allen</p>", "time": "2026-05-27T21:25:07.000Z"}, {"author": "Bron Gondwana", "text": "<p>Thanks Pete!</p>", "time": "2026-05-27T21:25:16.000Z"}, {"author": "Andrew Newton", "text": "<p>Thanks everyone</p>", "time": "2026-05-27T21:26:11.000Z"}]