TCMBC

TCMBC's avatar
TCMBC
npub1mhte...h0qn
TCMBC
If you are a company that is a specialist in email delivery for customers, and you want to claim support for STARTLS encrypted sessions to the greatest number of recipients, maybe you should be sure your company supports ECDSA based certs in addition to RSA. Sure, RSA is nearly 50 years old, while ECDSA was proposed a little over 30 years ago, but how many decades will need to pass before you support ECDSA certs? Joking/Sarcasm: I can under stand that something that is over 30 years old might be "too new" for antiquarian tech companies with nostalgia for Luddite beliefs to consider supporting, but please, let us know which decade you plan to make a decision. Is this an issue that "will be decided after heat death of the universe" kind of thing? And another thing, if you specialize in email delivery, why not also support TLS/1.3 ciphersuites with STARTTLS over SMTP sessions? All the cool kids support TLS/1.3. (It would be best if email could move off the need to use STARTLS and just expect everyone to use TLS without STARTTLS and impose the same requirements of host name matching (older mostly obsolete ) "CN" in subject or modern "SAN" for connected hostname and validate before delivery, but that is a more difficult change.) In other news: if you run a domain that received mail, check out MTA-STS: It can be a nice complement to using DANE/TLSA with DNS using DNSSEC for adding security to mail server certs.
Are you seeing complaints about your domain's email being refused for DMARC validation failures? Do you use multiple MTA service providers to send email? Does your TXT record in DNS for SPF include multiple mail service provide required "include:" entries? Please check the results of your records, drilling down through your includes, and included includes until the end, and count how many " a " and " ptr " and " mx " and " exist " you have, as each of those counts as a lookup. Each include adds one. Each include's include counts as another, on and on. Total up all your lookup and see if your SPF requires the receiving server to perform more than 10 lookup including the original for your domain, then review: I hope this helps someone out there!