Re: DANE and TLSA

2021-05-11 Thread Viktor Dukhovni
On Tue, May 11, 2021 at 08:21:50PM -0400, post...@ptld.com wrote: > It is my understanding if you publish DANE and TLSA records not only > must you be using DNSSEC (Which most big companies don't) but then your > mail server will not accept mail from anyone not using TLS 1.2+.

Re: DANE and TLSA

2021-05-11 Thread Ralph Seichter
* post...@ptld.com: > It is my understanding if you publish DANE and TLSA records not only > must you be using DNSSEC (Which most big companies don't) but then > your mail server will not accept mail from anyone not using TLS 1.2+. DNSSEC only ensures that DNS responses can be ve

DANE and TLSA

2021-05-11 Thread postfix
Viktor's announcement reminds me, It is my understanding if you publish DANE and TLSA records not only must you be using DNSSEC (Which most big companies don't) but then your mail server will not accept mail from anyone not using TLS 1.2+. Why would you want to do that and block