Hacker News new | past | comments | ask | show | jobs | submit login

DKIM is for an entire domain, not individual addresses, though.

But it can work for individual addresses as well. For instance, gmail uses DKIM. If they only DKIM sign an email if the user is logged in as the address they are trying to send as, then boom, DKIM is proof that the email from is not forged, and the only way to bypass it is to hack the account.

Sure, but why would the SMTP server sign an email with the wrong login?

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact
