I understand that, but it still doesn't address the include:xxx condition I outlined above. If we use an application service provider that sends email on our behalf, I have to get that provider to setup a custom header in the outbound email with a private cert I have generated for them. With SPF I can simply use an include: xxx to specify that I also trust vendorx.com to send mail for mydomain.com. I was inquiring if there is a facility for DKIM to support such a mechanism, which it doesn't seem like there is.
I can take a hardline with the ASPs and require they allow stamp the mail with my DKIM, but if you're not a large enough customer chances are they will say tough deal with it or go somewhere else.