Educause Security Discussion mailing list archives

Re: Notifications of external emails


From: Valdis Kletnieks <valdis.kletnieks () VT EDU>
Date: Wed, 8 Feb 2017 19:28:39 -0500

On Wed, 08 Feb 2017 11:43:30 -0500, Frank Barton said:

The problem comes then from modifying the body of the message, and that can
invalidate digital signatures (DKIM, S/MIME for example)

Not sure what can be done for a DKIM that covers Subject: if you rewrite it.

The simple trick to avoid breaking S/MIME is to restructure the message,
and wrap it in more mime:

--multipart/related
  -- your informational message header here 
  -- the original S/Mime/pgp/whatever here
     -- text/plain message body
     -- application/digital-signature

I'm pretty sure that MailMan is able to do the restructuring.  LSoft's Listserv
product and GMail don't try to do it.

You want it as a header, not a footer, so they read it before they read the
phish not after..

Attachment: _bin
Description:


Current thread: