Don't have an account? Sign up
If you're already signed up, please sign in
DANE for SMTP — the use of DNSSEC-authenticated TLSA records to declare and authenticate TLS support for SMTP servers and resist downgrade attacks.
The mechanism complements SPF, DKIM, DMARC, or TLS and addresses a separate need, such as preserving authentication through forwarding, validating a brand, defining an encryption policy, or reporting failures. It does not replace baseline email authentication.
DANE for SMTP — the use of DNSSEC-authenticated TLSA records to declare and authenticate TLS support for SMTP servers and resist downgrade attacks.
It conveys an additional verifiable signal between sender and receiver when ordinary authentication or transport encryption is insufficient for a specific delivery scenario.
Establish correct DNS, SPF, DKIM, DMARC, and TLS first, then satisfy the selected specification. Verify reports and actual message headers, not only the presence of a DNS record.