Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's quite a bit more accessible than DANE, so uptake has increased in the last few years. A bunch of high-volume operators support it, like gmail. But support also exists in newer MTA software like Stalwart, Maddy and ZoneMTA. (Though there are ways to add MTA-STS support to Postfix as well.)

MTA-STS has a great benefit that one doesn't need to deal with the antiquities of their registrars or TLD operators, just set up a few records and run a web server. WebPKI in general is also significantly better than DNSSEC. So you win twice.

Though MTA-STS doesn't cover the part between MUA and MSA unfortunately, I've seen an abandoned draft for MUA-STS but that's about it.



You can actually run MTA-STS on Cloudflare Workers so the web server piece isn't even necessary. It was fairly easy to implement and works well for me.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: