Since late 2021 there has been an increase in the use of DKIM Replay Attacks. While the potential for DKIM Replay Attacks was noted in the original DKIM RFC, bad actors were finally using them in ways that caused real trouble for large mailbox operators.

A number of proposals to address this threat were written up, and several are covered in this presentation from 2022. There was activity in the IETF DKIM Working Group, which had been revived in hopes of finding effective countermeasures, but nothing seemed to gain consensus and the working group went quiet.

But at IETF 121 in Dublin a new an Internet Draft was presented describing a new protocol that incorporated several of the proposals into DKIM, and new additions, being referred to as DKIM2. And this new effort appears to have strong support from Google and Yahoo.

For more details on DKIM2 refer to the Draft linked above, or see the second section of the DMARC.org presentation at the 7th JPAAWG General Meeting.