Authentication-Results: amazonses.com; spf=pass (spfCheck: domain of seahaven.com designates 209.85.219.70 as permitted sender) client-ip=209.85.219.70; envelope-from=apm+bnc@seahaven.com; helo=mail-qv1-f70.google.com; dkim=pass header.i=@seahaven.com; dmarc=none header.from=hxgnsmartcloud.com; From: APM To: apm@int.seahaven.com Subject: Synthesized SES-stamped auth-pass fixture for the WO handler auth seam Content-Type: text/plain; charset="utf-8" This is a synthesized SES-stamped fixture (the one new fixture Phase 8 permits). Its Authentication-Results header block is copied verbatim from WO_SES_HEADER in tests/test_ses_auth.py: authserv-id amazonses.com with dkim=pass header.i=@seahaven.com, so it authenticates for ALLOWED_DKIM_DOMAINS=seahaven.com exactly like production mail. Its body does not match any deterministic WO template, so processing falls through to the AI-fallback path (Bedrock is faked in the test). It carries no real signature or receipt tokens -- it is not scraped mail.