top | item 33232372

(no title)

Koenvh | 3 years ago

DANE is gaining adoption primarily when it comes to email - browsers are still hesitant.

discuss

order

tptacek|3 years ago

Browsers have refused to implement DANE for the last ten years. In the meantime, the major email players came up with MTA-STS, and alternative to DANE that cites lack of DNSSEC adoption as one of its rationales.

If you send email today, it's vanishingly unlikely that any DNSSEC will happen; email is complicated and email infrastructure tends to shut people's brains off (I know it does for me) but you can just look at the tiny slice of domains that are actually DNSSEC signed and see that there's no meaningful adoption.