Don't DKIM-oversign Sender header field
Closed
good first issue
mta-out
security
- Dominant language
- Go
- Stars
- 6.1k
- Forks
- 327
- PR merge metrics
- No merged PRs in 30d
Description
Sender header field is oversigned even though it is not documented. To make maddy more compatible with the mailing list, it should be signed only if it is included and NOT oversigned.
Contributor guide
Research direction
No file or test is named. Start by locating the DKIM signing entry point and its handling of the Sender header; verify the behavior against the issue's included-versus-oversigned distinction. Done means Sender is signed when present but is not added as an oversigned field.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go
- Domain
- authentication
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 48/100