Feature changes: ================ Verify X-Mailman-Original-DKIM-Signature (discard the leading 19 chars during verification passes). Add a "forced authentication policy". If a domain has a loose policy or no policy at all, setting this flag rejects if no authentication. The flag is set by passing add_dmarc > 1 in db_sql_domain_flags. Bug fix: ======== The function to find the organizational domain from the PSL lacked backtracking.