Home / Blogs

Searching for Truth in DKIM: Part 5 of 5

J.D. Falk

Throughout this series of articles we've been talking about DKIM, and what a valid DKIM signature actually means.

Part 1 explained that the DKIM "d=" value identifies the domain name which signed the message, which may be different from the author of the message. Part 2 described how the author domain can gain some control over whether any other domain name should ever sign a message purporting to be From: that author domain. Part 3 discussed how the reputation of a d= domain leads to a reliable determination of trustworthiness, while part 4 reminded us that truth cannot be assumed until trust is certain.

What this means for senders (of any type) is that with DKIM, you're protected. On the internet, your domain name is a statement of your brand identity — so by signing messages with DKIM, you can finally, irrevocably tie those messages to your brand. As your brand reputation improves, so does the deliverability of your messages. And if you change IP addresses, your reputation follows.

What this means for ESPs who send on behalf of others is that you can finally send your client's mail using your client's reputation. I didn't get into this earlier, but you can even sign the message with both your client's d= domain and your own d= domain, likely resulting in a combined reputation score for that particular message. Steve Atkins goes into more detail here. This concept is so new, though, that it isn't yet clear what the best practice will be.

What this means for receivers (of any type) is that there's now a much more useful identifier to hang reputation on. You can stop fiddling with IP addresses, thus reducing the risk of false positives due to shared IPs, or forwarding, or a formerly bad IP being reassigned to a good sender. You can develop more complex and accurate reputation models when a message has multiple signatures, thus multiple d= identifiers. And in a few years, you'll be able to safely assume that anyone who isn't signing with DKIM doesn't really care if their mail gets delivered.

What this means for users — the end recipients of all these messages — is still unclear. A few ISPs have experimented with icons or text indicating that a message is signed, but (as we know) that alone doesn't mean it's trustworthy. There are many other interesting ideas floating around, though. A message signed by a trusted domain will probably be delivered to the inbox, but that's old news. It might be permitted to include rich media elements: images, video, etc. Most mail clients already indicate when a message is From: an address in your address book or contact list; I could easily imagine this feature being upgraded to only show the address book icon when the message was signed by the appropriate domain. The possibilities are endless, and I'm certain we'll see some interesting experiments over the next few years.

(This article was originally published by Return Path.)

By J.D. Falk, Internet Standards and Governance. Visit the blog maintained by J.D. Falk here.

Related topics: Domain Names, Email, Security, Spam

WEEKLY WRAP — Get CircleID's Weekly Summary Report by Email:

Comments

To post comments, please login or create an account.

Related Blogs

Related News

Topics

Industry Updates – Sponsored Posts

Top Level Domain Holdings Raises $14M for New gTLDs

.ORG COO Discusses Priorities With DailyVista, Pursuit of .NGO Domain

StarHub to Acquire '.starhub' New Top-Level Domain

ARI Registry Services Signs 21 Contracts in the First Week of New TLD Applications

MarkMonitor to Exhibit at Internet Tech Policy Exhibition and Reception to be Held on Capitol Hill

Sedari Signs With Dot Moscow Bidders

.ORG, The Public Interest Registry Welcomes Nancy Gofus As Chief Operating Officer

Minds+Machines Works with .bayern

The New Domain For Japan, JP.NET, Launches With Exclusive Invitation to Trademark Owners

Verisign to Award New Infrastructure Research Grants

Being a .PRO When Choosing a Registry Services Partner

Afilias Acquires Registry Services Corporation, .PRO

Thoughts on Applying for a Generic Top-Level Domain

Sedari Launches "Guess the Numbers Game" for New TLD Program

dot Brand Makes Its Debut: Afilias Advises Companies to Act Now for Successful TLD Applications

Facets of gTLD Registry Technical Operations - Registry Services

Technology and Finance Industries to Dominate New gTLD Applications

.CO Internet Selects Sedo to Broker Previously Unreleased .CO Domain Names

Sedari and NCC Launch Programme to Assist New Registry Operators

Nixu SNS 2.5 Series Gives Fresh Views on DNS

Hot Topics

Minds + Machines

Top-Level Domains

Sponsored by
Minds + Machines
Afilias

DNSSEC

Sponsored by
Afilias
Verisign

Security

Sponsored by
Verisign
dotMobi

Mobile

Sponsored by
dotMobi
Neustar UltraDNS

DNS

Sponsored by
Neustar UltraDNS