Any DKIM-Signature header fields using the "i=" tag MUST have the same domain value on the right-hand side of the "@" in the "i=" tag and the value of the "d=" tag. That is, the "i=" domain MUST NOT be a subdomain of "d=". Use of this flag is RECOMMENDED unless subdomaining is required.
When
s
is in a key's flags list, then:(RFC 6376 Section 3.6.1)
Currently, go-msgauth's DKIM verifier unconditionally allows the
i=
domain to be a subdomain ofd=
.