Forgot login?
Home Forum Forum
DNSstuff User Community
November 21, 2009, 03:16:18 am *
Welcome to the DNSstuff Community Forums
News: New! Mail Server Test Center - Another Industry first! This Test Center combines a series of real-time tests and an easy-to-interpret results dashboard.  This new application will allow you to manage and monitor email with greater safety and reliability.
 
   Home   Help Search  
Pages: [1]
  Print  
Author Topic: DKIM support  (Read 1459 times)
hireahit
New Member
*
Posts: 5


View Profile
« on: July 09, 2009, 07:42:17 pm »

Would it be possible to add a DKIM ADSP record similar to how SPF records are noted in a DNS Report?
Logged
hall
New Member
*
Posts: 21


View Profile
« Reply #1 on: September 24, 2009, 01:42:24 pm »

This is a great idea..... DNSStuff, hello?
Logged
mike_keighley
Hero Member
*****
Posts: 906


View Profile
« Reply #2 on: September 24, 2009, 07:00:11 pm »

What ?  "Domain Keys" is a great idea ?  Don't make me laugh / hurl.

Or ?  "a tool to check and interpret DK records" is a great idea ?  Maybe.  How about some more detail to go on ?
Logged
hireahit
New Member
*
Posts: 5


View Profile
« Reply #3 on: September 24, 2009, 08:04:46 pm »

I thought the request was fairly straight forward: Show DKIM ADSP records similar to how SPF records are displayed in a DNS report.

In other words, report if a DKIM ADSP record exists or not, and the status of the record if it exists.

If you don't know what DKIM ADSP records are, you might want to look it up rather then looking confused.
Logged
mike_keighley
Hero Member
*****
Posts: 906


View Profile
« Reply #4 on: September 25, 2009, 12:05:06 am »

Quote
If you don't know what DKIM ADSP records are, you might want to look it up rather then looking confused.

Oh, I have a fair idea what they are, thanks.  What I am not so clear on is how wide adoption is, whether the effort would be justified, whether anything based on self-certified keys is ultimately worth the electrons it is signed with ...

Since you draw a comparison with SPF, however, I can't help noting that an ADSP seems to be merely a statement of signing policy by the sending domain.  Is it actually possible to do meaningful validation of an ADSP record itself, in the absence of a particular DKIM-signed email ?
Logged
hireahit
New Member
*
Posts: 5


View Profile
« Reply #5 on: September 28, 2009, 08:36:26 am »

You apparently don't have a clue what DKIM ADSP records are or how they work -- Fair enough.

DKIM records themselves cannot be evaluated without seeing a signed message unless zone transfers are enabled since the name of the selector isn't otherwise known in advance.

DKIM ADSP records, on the other hand, allow a recipient to know whether or not to reject a message which either fails to validate, or isn't signed at all.  As a result, similar to SPF, the DKIM ADSP record is in a known location and does not require a correctly signed messages to retrieve the DKIM ADSP record.

I'd love to suggest verifying the existence and validity of DKIM records, but since this isn't possible without knowing the selector, it's probably more hassle then it's worth.
Logged
dbass99
Hero Member
*****
Posts: 501


View Profile
« Reply #6 on: October 02, 2009, 03:57:17 pm »

Thanks for making the request.  We are always looking for ways to help our customer base with configuration and error checking. 

There are many RFC's that are currently being implemented by our users that may, as yet, not be an official standard.  We are are working on our tools and have discussed a possible method by which our users may be able to test records based on pure conformity to standards, conformity to popular proposed standards and/or general best practices.

Please feel free to send your ideas to our forum or directly to us in email.  We are listening and collecting every idea to review for our future features list.

Making the DKIM ADSP record visible like the SPF to know if it is unknown, all, or discardable would be of interest to certain people.
Logged
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.9 | SMF © 2006-2009, Simple Machines LLC Valid XHTML 1.0! Valid CSS!