Experience with DKIM signatures and DCC

John L johnl@iecc.com
Sat Mar 29 17:42:08 UTC 2008

> Instead of only whitelisting by DKIM success,
> why not also blacklist by DKIM failure or IP address reputation?

I wouldn't do anything with DKIM failure at this point, since there are 
way too many reasons that legit mail could arrive with a valid signature.

Whitelisting DKIM sigs from people you know and white and blacklisting of 
IPs with particularly good and bad histories should work well.


