← Back to context

Comment by parliament32

4 months ago

> For mail, couldn't we come up with a mail-DNS, that authenticates senders?

So RFC 7672? https://datatracker.ietf.org/doc/html/rfc7672

I have no knowledge of DANE but its reliance on DNSSEC makes me worried that it would be difficult for people to adopt it.

Also, I think it solves a different problem: it prevents spoofing/MITM but what about legitimate certificates? We would still need CAs that actually curate their customers and hold them accountable. And we would need email servers/clients to differentiate between strict CAs and ones that are used solely for encryption purposes.

I don't know that DNS should be applied to emails as is anyway but I find it could force spammers to operate with publicly available information which would make holding them accountable easier.