147
Comments (6)
sorted by:
You're viewing a single comment thread. View all comments, or full comment thread.
5
Long_time_lurker [S] 5 points ago +5 / -0

Spread it everywhere you can! The Github gives a great technical argument.

When you see shills claiming "but DKIM doesn't validate the body" point them at the damned bh parameter in the signature. That stands for "body hash" and so yes, this signature does validate the body even if DKIM in general can't be relied upon for that.

There's someone doing that on reddit's conspiracy right now. They're wrong and they can be proven wrong, so please help call them out on that!