Conversation

I wonder how long it'll be before large companies require DNSSEC (and verify) + TLS for delivering email 2FA codes. My guess is never, despite the relative ease that those codes can be spied upon.
4
14
Replying to and
It's less bad than SMS but barely anything will send email to Gmail with authenticated encryption because they only offer MTA-STS and while setting up receiving MTA-STS is just a minor pain, setting up outbound MTA-STS verification is far worse. Gmail's max-age is only 24h too.
2
1