[Bimi] BIMI headers that an MTA must delete

Andrew C Aitchison <andrew@aitchison.me.uk> Wed, 11 June 2025 11:10 UTC

Return-Path: <andrew@aitchison.me.uk>
X-Original-To: bimi@mail2.ietf.org
Delivered-To: bimi@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id C03E3339E599 for <bimi@mail2.ietf.org>; Wed, 11 Jun 2025 04:10:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -4.401
X-Spam-Level:
X-Spam-Status: No, score=-4.401 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=aitchison.me.uk
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id lxGi57gUgJUp for <bimi@mail2.ietf.org>; Wed, 11 Jun 2025 04:10:52 -0700 (PDT)
Received: from mx1.mythic-beasts.com (mx1.mythic-beasts.com [IPv6:2a00:1098:0:86:1000:0:2:1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id BA946339E594 for <bimi@ietf.org>; Wed, 11 Jun 2025 04:10:52 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=aitchison.me.uk; s=mythic-beasts-k1; h=Subject:To:From:Date; bh=Ca/lXbVNLZwmbb3V9HwsKHYKzMxlUhmx40v9DrPcPVo=; b=SAZqx+hUsSDbxAw5EyeeuyUmim OGCGNZe6n2SIMLnZ74fzYQn/rKLuZXF1NT4Qbr4FGFfsYh9FyNX4cbUKNCqs/GY35e8SrCr0pqGbZ 238HUV2bD7At/yiP4ikHNRLmWaEgZEMy2I+p6jNEF2m0P/Y6oQdTdoDhNKIS8yNzb+Wsa4CVJNsjN uVTDRgfLxuvIQhYpIMSvLNJXASpTzt+v+YSBfwwmkgT4BkUSSfmubegFslqUJAYP3vfTwtaR3RtXi ohZBBOpnOxUdajS/9gfjbxp8RF04867EiYn85nkYKEuzZGfEensIQXRmFAdEDb5dNnw1LRC7C70U+ Ln/HGpjw==;
Received: by mailhub-cam-d.mythic-beasts.com with esmtpsa (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from <andrew@aitchison.me.uk>) id 1uPJM3-00F5gh-Ov for bimi@ietf.org; Wed, 11 Jun 2025 12:10:52 +0100
Date: Wed, 11 Jun 2025 12:10:49 +0100
From: Andrew C Aitchison <andrew@aitchison.me.uk>
To: bimi@ietf.org
Message-ID: <5cafd3c4-1f4d-01fa-89ec-ddddf555f8e5@aitchison.me.uk>
MIME-Version: 1.0
Content-Type: text/plain; format="flowed"; charset="US-ASCII"
X-BlackCat-Spam-Score: 0
Message-ID-Hash: E6KRV7VO2M75HCKHUSFIXVWK6MJOMKS4
X-Message-ID-Hash: E6KRV7VO2M75HCKHUSFIXVWK6MJOMKS4
X-MailFrom: andrew@aitchison.me.uk
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Bimi] BIMI headers that an MTA must delete
List-Id: Brand Indicators for Message Identification <bimi.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/bimi/sGNGXW1APoTUlTW9CxiJ1ZPW17o>
List-Archive: <https://mailarchive.ietf.org/arch/browse/bimi>
List-Help: <mailto:bimi-request@ietf.org?subject=help>
List-Owner: <mailto:bimi-owner@ietf.org>
List-Post: <mailto:bimi@ietf.org>
List-Subscribe: <mailto:bimi-join@ietf.org>
List-Unsubscribe: <mailto:bimi-leave@ietf.org>

I was re-reading the list archive and came across this from May 2024:
   AFAIK No MUAs actually implement it using those two headers, feel to
   list any. Current implementations seem to use Authentication-Results (or
   equivalent) but usable implementations seem to be limited to a specific
   pairings of MTA+MUA. This is in theory because some MTAs might be
   grossly insecure and do not remove/replace the AR header properly. (But
   at that point I'd say the MUA has bigger problems than forged BIMI.)
https://mailarchive.ietf.org/arch/msg/bimi/zSwqK5yyTuEYnuumvUv1NZEqSQs/

1. Could the draft-RFC be updated to say that the AR header MUST be 
removed/replaced, as well as (instead of ?) BIMI-Location, BIMI-Indicator
or BIMI-Logo-Preference ?

https://datatracker.ietf.org/doc/html/draft-brotman-ietf-bimi-guidance 
5.2.1 does suggest removing all BIMI-* headers but not 
Authentication-Results, upon receipt - but only a "should" not a "MUST" or 
"must".

https://datatracker.ietf.org/doc/html/draft-brand-indicators-for-message-identification
only disusses removing BIMI-Location, BIMI-Indicator and 
BIMI-Logo-Preference

2. You cannot really blame a non-BIMI-supporting MTA for *not* removing 
any of these headers. Calling them "grossly insecure" is not appropriate.
If you wish them to remove unsafe incoming headers, please make the 
(draft) standard clear on what they MUST do.

It is *not* satisfactory that we have a protocol currently in use across
the internet whose standard says that certain things MUST be done
*by third parties* to make it secure,
but does not accurately say what these things are.

-- 
Andrew C. Aitchison                      Kendal, UK
                    andrew@aitchison.me.uk