[ mailman-Patches-1287546 ] Remove DomainKeys (and similar) header lines

Fri Dec 16 16:16:41 CET 2005

Patches item #1287546, was opened at 2005-09-11 10:08
Category: mail delivery
Group: Mailman 2.1
Status: Closed
Resolution: Accepted
Priority: 5
Submitted By: Joe Peterson (skyrush)
Summary: Remove DomainKeys (and similar) header lines

Initial Comment:
This simple patch removes the header lines containing
keys used in DomainKeys (Yahoo) and DKIM.  The keys, if
left in the header, will make the email seem forged or
altered to the recipient, since Mailman alters
header/body info.  If the keys are removed, the MTA
will generate new keys (if this is installed on the host).



Comment By: Marko Karppinen (markonen)
Date: 2005-12-16 17:16

Logged In: YES 

I think this is problematic. For intra-organizational lists, removing the 
DomainKeys header works as advertised. However, if a person from a 
DomainKeys-enabled domain posts onto an external list, there is a potential 
for error.

If the sender's domain's DomainKeys settings specify that the domain does 
not send unsigned mail, external MTAs can and will drop an email from that 
domain if the DomainKeys headers are removed.

To make DomainKeys work with mailman as expected, admins have two 
1) Deliver the message as-is, without modifying the Subject header or 
message body (or any header indicated to be signed). The original 
DomainKeys signature will then work.
2) If modifying the message is necessary, the mailing list will have to rewrite 
the From: header in order not to claim that the message originated in the 
DomainKeys -protected sender domain.

Removing the DomainKeys header will only be relevant in the case 2) above. 
For 1) -- the preferred solution for many lists -- it is actively harmful. 
Therefore, automatically removing the DomainKeys header is NOT the way to 


Comment By: Barry A. Warsaw (bwarsaw)
Date: 2005-09-13 00:59

Logged In: YES 

Applied to both Mailman 2.1 branch and trunk (2.2)


Comment By: Joe Peterson (skyrush)
Date: 2005-09-11 10:09

Logged In: YES 

Attached is the patch.


