Conversation

Tip: if you're using Gmail for mail on your own domain, change your MX records to mx[1-4].smtp.goog to get DNSSEC+DANE protection on your email.
3
6
Replying to
It's just DNSSEC without DANE right now. If a lot more people use it, maybe they'll take that as a signal for people wanting DANE and add records. It would be really easy for them. Can set up MTA-STS with it though, and DNSSEC makes that work better than just Trust On First Use.
1
1
Replying to
I don't think they have TLSA records for their mail servers. They could easily add them, especially since they use the same TLS infrastructure they do elsewhere and they use pinning for their web sites, update servers, etc. via pinning the valid CAs for their properties.
2
1
Replying to and
There's a good chance they would be completely willing to add TLSA records to those if someone got in touch with the right person and communicated it properly, especially mentioning the similarity to the pinning they use elsewhere.
1
1