Spread it everywhere you can! The Github gives a great technical argument.
When you see shills claiming "but DKIM doesn't validate the body" point them at the damned bh parameter in the signature. That stands for "body hash" and so yes, this signature does validate the body even if DKIM in general can't be relied upon for that.
There's someone doing that on reddit's conspiracy right now. They're wrong and they can be proven wrong, so please help call them out on that!
Spread it everywhere you can! The Github gives a great technical argument.
When you see shills claiming "but DKIM doesn't validate the body" point them at the damned bh parameter in the signature. That stands for "body hash" and so yes, this signature does validate the body even if DKIM in general can't be relied upon for that.
There's someone doing that on reddit's conspiracy right now. They're wrong and they can be proven wrong, so please help call them out on that!