|
|
|
|
|
by brightball
20 days ago
|
|
There are a few gaps with DKIM. 1. You have to set it up on every sending server. It's easier today but it wasn't always 2. You have to periodically rotate each of the keys that you setup because they can be cracked/stolen. Soon as somebody steals your key, they can impersonate anyone sending email from your domain. 3. Receiving email servers have no way of knowing if a message they received without a DKIM signature is supposed to include a DKIM signature, so simply not including one creates a scenario where receiving mail servers have to guess if the message was really from you. |
|
Depending on your perspective, this can be either a feature or a bug.