ietf-smtp
[Top] [All Lists]

Re: [ietf-smtp] DANE penetration for MTA/MTA interactions

2021-03-24 20:03:49
On Thu, Mar 25, 2021 at 12:03:25AM +0000, Richard Clayton wrote:

Indeed ... but it fixes the actual real world problem which the large
providers have

Among the top 5000 Alexa domains, MTA-STS is enforced on 16:

    google.com 1
    mail.ru 116
    gmail.com 303
    xfinity.com 675
    openstreetmap.org 710
    wp.pl 1205
    comcast.net 1569
    jetbrains.com 1583
    protonmail.com 2110
    xs4all.nl 2591
    drugs.com 2664
    rte.ie 2775
    arbeitsagentur.de 3784
    govtrack.us 4313
    gsa.gov 4721
    o2.pl 4781

Meanwhile, DANE TLSA records are published for the MX hosts of 30:

    debian.org 271
    ietf.org 336
    xfinity.com 675
    web.de 772
    gmx.net 872
    openssl.org 954
    freebsd.org 962
    bund.de 1304
    navy.mil 1359
    comcast.net 1569
    isc.org 1677
    mpg.de 1816
    cwi.nl 2010
    protonmail.com 2110
    habr.com 2406
    xs4all.nl 2591
    startpage.com 2673
    one.com 2711
    univie.ac.at 2792
    torproject.org 2840
    bayern.de 3276
    uni-muenchen.de 3560
    mail.com 4123
    tum.de 4152
    govtrack.us 4313
    uib.no 4457
    rijksoverheid.nl 4633
    utwente.nl 4651
    cuni.cz 4744
    thalesgroup.com 4820

Just 5 out of the 5000 have both MTA-STS and DANE live:

    xfinity.com 675
    comcast.net 1569
    protonmail.com 2110
    xs4all.nl 2591
    govtrack.us 4313

--
    Viktor.

_______________________________________________
ietf-smtp mailing list
ietf-smtp(_at_)ietf(_dot_)org
https://www.ietf.org/mailman/listinfo/ietf-smtp