[Bimi] Re: BIMI headers that an MTA must delete

Taavi Eomäe <taavi@zone.ee> Mon, 16 June 2025 19:52 UTC

Return-Path: <taavi@zone.ee>
X-Original-To: bimi@mail2.ietf.org
Delivered-To: bimi@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 8116735A0F7E for <bimi@mail2.ietf.org>; Mon, 16 Jun 2025 12:52:45 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=zone.ee
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PB7spRO6FUOJ for <bimi@mail2.ietf.org>; Mon, 16 Jun 2025 12:52:44 -0700 (PDT)
Received: from MTA-244-85.TLL01.ZONEAS.EU (mta-244-85.tll01.zoneas.eu [85.234.244.85]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 3FB9A35A0F79 for <bimi@ietf.org>; Mon, 16 Jun 2025 12:52:43 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=zone.ee; q=dns/txt; s=zone; bh=6a9HvyLCsuztDlmWSwYP/8ByjrlhNxW6FnPRxFH8GpM=; h=from:subject:date:message-id:to:mime-version:content-type:content-transfer-encoding:in-reply-to:references; b=dGkrZKkzQdsOln3FBH9YTZc8N/XiULZeuCbqM+5yS8jD8E7LvrkfV5qmcQBUHzvmID3jUGKB9 7oslr/YbOmqailNRkNdT8COKdFFqjzMLy8esnwllJ1p4RzFcYSTtBXHJKgt8TfYKFzJ9oB6Iq7x JIYM/DvZxhJHDt/UsBbuoClhmj+lckkcyINSQt1iJmtGS0PmXYx3cgVd1yvUkzN8FN0MrRuf4/G 2Zlirz9i0rG4682Gp6epSVAEaWGi+0vBWOyNwbMvNROatNIF/FbxPd2ttNiOdz/bx3gDVFylXB9 kZbZWK9VvxH2Ryhs60pF/shdqTLI8K5J8YHVqbRnKVbQ==
Received: from [192.168.50.3] [217.146.66.6] (Authenticated sender: zmail526721[taavi@zone.ee]) by MTA-244-85.TLL01.ZONEAS.EU (ZoneMTA Forwarder) with ESMTPSA id 1977a4d0fb90008ab8.002 for <bimi@ietf.org> (version=TLSv1.3 cipher=TLS_AES_256_GCM_SHA384); Mon, 16 Jun 2025 19:52:40 +0000
Message-ID: <b151a989-0249-4c3d-aad0-58c457c785b3@zone.ee>
Date: Mon, 16 Jun 2025 22:52:39 +0300
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
To: John C Klensin <john-ietf@jck.com>, bimi@ietf.org
References: <5cafd3c4-1f4d-01fa-89ec-ddddf555f8e5@aitchison.me.uk> <e489103e-1cb5-45ec-a4c1-298fb02bf50c@zone.ee> <EFAA6635745E50A0A13143BE@PSB>
Content-Language: en-US
From: Taavi Eomäe <taavi@zone.ee>
In-Reply-To: <EFAA6635745E50A0A13143BE@PSB>
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 8bit
Message-ID-Hash: YUD3DTXQMXSZSCH6WEW6JVPWLCNJ4LWV
X-Message-ID-Hash: YUD3DTXQMXSZSCH6WEW6JVPWLCNJ4LWV
X-MailFrom: taavi@zone.ee
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Bimi] Re: BIMI headers that an MTA must delete
List-Id: Brand Indicators for Message Identification <bimi.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/bimi/WKQ4EE9Bjmi-iV9XTSccm_F4Asw>
List-Archive: <https://mailarchive.ietf.org/arch/browse/bimi>
List-Help: <mailto:bimi-request@ietf.org?subject=help>
List-Owner: <mailto:bimi-owner@ietf.org>
List-Post: <mailto:bimi@ietf.org>
List-Subscribe: <mailto:bimi-join@ietf.org>
List-Unsubscribe: <mailto:bimi-leave@ietf.org>

Hi,

I think we actually agree on quite a few points here, I'll try to 
clarify a bit.

On 16.06.2025 19:02, John C Klensin wrote:
> RFC 5321 and, more important, the Internet Standard
> draft-ietf-emailcore-rfc5321bis-43 (for which a Protocol Action
> Notice was posted at the end of April), strongly discourage MTAs from
> looking at header fields at all, much less tampering with them.

The current draft does instruct to tamper with BIMI-* headers. My 
suggestions were exactly to avoid that, to take what's there and provide 
an assessment in an header (A-R). Like it is done with DMARC, SPF and DKIM.

In some previous thread it has been said that it might be possible to 
forge AR (or BIMI-*) when it's not added by the last hop/recipient. I 
presume in the case of some old MTA that does not know about the 
header(s), does not do DMARC, SPF or DKIM, certainly not BIMI. BIMI 
obviously can't dictate what they should be doing. But such a system 
would also not be advertising BIMI support to a MUA downstream.

This would basically be your case number 1. To avoid having to dictate 
anything to any MTAs that are unaware, avoid creating situations where 
the entire chain has to be aware, avoid all that complexity. When all 
that could matter is that an aware MTA taking part in the final delivery 
validates signed headers, records that in the headers and that the MUA 
is signaled somehow that "that last hop was BIMI-aware".


Best,
Taavi