On Sat, Sep 26, 2026 at 10:02:37AM -0700, Mel P via Postfix-users wrote:
> > Well, that's interesting an potentially useful data. Have you been able
> > to examine a TLS protocol trance of an attempted handshake?
>
> Yes, but the cause is terribly boring: disjoint cipherlists.
Thanks, makes sense and a relief there's nothing more problematic
involved.
> > If you did have TLSA records in place, they existed so fleetingly that
> > the DANE survey (running once a day) never managed to record their
> > existence. DNSSEC-signed MX records pointing to the same DNSSEC-signed
> > MX hosts date back to July 30 2019...
>
> They were in the public horizon for half an evening--just long enough to
> blow up delivery.
Good to hear your systems are well monitored.
> p.s., do you have a link for the DANE survey mentioned?
https://stats.dnssec-tools.org
https://stats.dnssec-tools.org/about.html
https://stats.dnssec-tools.org/explore
And while I'm at it, always worth a mention:
https://dnssec-stats.ant.isi.edu/~viktor/x3hosts.html
There are other monitoring tools, but these are mine:
https://github.com/vdukhovni/danecheck
https://list.sys4.de/hyperkitty/list/[email protected]/message/6723WDBLPYWSXAORTAJR7EPAIOFAP5N4/
If you have multiple live certs (RSA + ECDSA, for example), the Haskell
check may only cover one of the two algorithms. The "danesmtp" bash
function over OpenSSL may be more flexible in that regard, but does not
automatically handle MX lookup and coverage of all IP addresses.
Another option is:
https://github.com/sys4/smtp-dane-verify
--
Viktor. 🇺🇦 Слава Україні!
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]