It appears that Ben Schwartz  <[email protected]> said:
>To be concrete: suppose an untrusted party shows up and says "Hey can I add a 
>new TXT record to your zone?  It's not at any name you're using.".  Without 
>DCV,
>this is potentially safe.  This party can't influence the behavior of the 
>names you care about.  With DCV, this is totally unsafe.  So DCV introduces a
>(arguably) new assumption about DNS zone behaviors.

Um, OK.  Please add this TXT record at a name I am pretty sure you are not 
using.  I would never dream of sending
forged mail and pretending it was from you.

notben._domainkey TXT "v=DKIM1; h=sha256; 
p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAu7YaubcN8r5Jsj6NWlSda8Gs4eZFpYeFDRJcOd7ICfZvjhO44t7TDk/RX3GPi9IU6OQBnwIU1fz3MdIusgC7PjR2VhTRTSGmKzDtOTWE8oI0MF/Ppq6TORY0ZVi/ioDAH7E+bqyNj74TdPVWLLWnwk/htsJE1qCVGhXDkUZETKCWzH1MLYcsUORnGM2PfE"
 
"CoTP2S+KmnraaK4hiLRPQ0bHeeeiK+NX61ymmoavPmAZkORx7bZRtabEMy75vZr/NyunCRUq/071hpIcIX84ztC8hNdC9rLT0Lejsv4hXCwsPSqZ7H0Be9wC0JyXkEbxdHq+EtzTVP9npik7HZ/QjSNwIDAQAB"

R's,
John

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to