Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Regarding DKIM, Cloudflare recommends[1] a record of "v=DKIM1; p=", whereas this recommends deleting all "_domainkey" records. Is there a difference?

[1] https://www.cloudflare.com/learning/dns/dns-records/protect-...



"v=DKIM1; p=" is a perfectly valid DKIM record. It simply tells that the key has been revoked and you should no longer trust new emails signed with previous keys. The practical effects should be similar, although maybe there's a non-compliant server that retroactively revokes older emails (this should not happen, but I can only speculate).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: