@dalias
Cheers. In context of your other reply this makes sense and makes @riastradh post much clearer!
So effectively there is a school of thought that says for #dkim to be both effective and not a threat you would need to be able to
• generate a private key per email
• insert it into the header
• sign the entire message
• publish the dkim record during transit
• profit...