dkim_verifier icon indicating copy to clipboard operation
dkim_verifier copied to clipboard

Feature request: ignore expired signatures

Open sersorrel opened this issue 5 months ago • 3 comments

Some DKIM signatures have relatively short expiry periods (e.g. expiry timestamp 24 hours or less beyond the signature timestamp). If I don't open Thunderbird for a day, this results in a lot of false-positive DKIM warnings.

Would you consider adding a feature to improve this situation? e.g. an option to:

  • ignore expired signatures entirely (like the existing advanced settings for weak keys/sha1/...)
  • check signatures based on the time the mail was received at the server, if known (e.g. Received headers, Delivery-date header, ...)

sersorrel avatar Sep 01 '24 16:09 sersorrel