[pfx] Re: new waves of connect/disconnect from *.outlook.com; any add'l pfx configs useful for further remediation?

2023-10-17 Thread Markus Ueberall via Postfix-users
On 17.08.23, 01:48 Viktor Dukhovni wrote via Postfix-users: So far, the pattern of Microsoft's outbound systems disconnecting immediately after a completed TLS handshake strongly correlates with a broken TLSA setup. For the record: I stumbled across this a couple of days ago when I received a

[pfx] Re: new waves of connect/disconnect from *.outlook.com; any add'l pfx configs useful for further remediation?

2023-10-18 Thread Markus Ueberall via Postfix-users
On 17.10.23, 18:42 Viktor Dukhovni wrote via Postfix-users: On Tue, Oct 17, 2023 at 05:47:11PM +0200, Markus Ueberall via Postfix-users wrote: For the record: I stumbled across this a couple of days ago when I received a message on LinkedIn telling me that a number of e-mails sent via

[pfx] Re: new waves of connect/disconnect from *.outlook.com; any add'l pfx configs useful for further remediation?

2023-10-18 Thread Markus Ueberall via Postfix-users
On 18.10.23, 22:11 Markus Ueberall wrote via Postfix-users: I just tried an explicit "_25._tcp" CNAME as suggested above (using the shared RRset) /alongside/ the existing "*._tcp" CNAME which I did not want to remove/replace for one domain ("D1") while keeping my aforementioned setup for a seco