Re: [ietf-smtp] SMTP Over TLS on Port 26 - Implicit TLS Proposal

2019-01-07 06:15:23
On 07/01/2019 12:03, Jeremy Harris wrote:
On 07/01/2019 11:34, Paul Smith wrote:
A simple TXT record saying "This domain's MTAs support STARTTLS (and,
possibly, optionally, this is the certificate fingerprint)" would seem
useful and not need anything else, and would protect against STARTTLS
downgrade for any sender willing to support it.
Starting to look like a DANE TLSA record...

Yep - but without needing DNSSEC, which seems to be the OP's problem with DANE.


