I'm considering writing a zine about owning a domain! (DNS! registrars! certificates! TLS! HSTS! MX records!). What questions do you have about domains? Will try to answer as many as I can.
234
159
2,318
This Tweet was deleted by the Tweet author. Learn more
Also really worth noting that email has no authenticated encryption without setting up MTA-STS and/or DANE TLSA records. Other email servers can't validate your server's certificate without doing this. Ideally, set up both, since many servers only use one of these to validate.
Google only uses MTA-STS. Many email servers in Europe use DANE. There's not much overlap where both are used.
Setting up an email server securely where you have authenticated encryption for inbound + outbound along with anti-spoofing for inbound + outbound is far from trivial.
As a great example of the difficulty in doing it, Google still uses DMARC p=none for http://gmail.com due to backwards compatibility concerns over broken email setups. That means sending spoofed emails as *@gmail.com works. Can be detected as likely spoofed but is allowed.
It's not trivial even if you're outsourcing to another provider. You still have to set up SPF, DKIM, DMARC, MTA-STS, DNSSEC and ideally TLSA records. Email security heavily depends on DNS security even if you don't use DANE. Can set it up securely, but most other servers won't.