Outbound DANE validation support added to Exchange Online

Support for inbound mail to follow hopefully next summer

The Microsoft logo at Microsoft's French headquarters in Issy-les-Moulineaux

In spring of this year, Microsoft enabled DANE validationfor outbound mail traffic. Exchange Online users don't need to change any settings or actively enable the feature. The security check is performed automatically whenever mail is delivered to external mail servers (MX gateways).

DANE for inbound traffic – in other words, the use of DNSSEC and publication of TLSA records for mail – isn't yet supported, even though users have long been asking for it. However, Microsoft says that enabling DANE support for inbound traffic is now planned for next summer.

High adoption in the .nl zone

We started incentivising the use of DANE security for inbound mail in July 2019, through our Registrar Scorecard scheme. As the graph below shows, DANE adoption subsequently increased considerably [1, 2, 3] and now stands at nearly 20 per cent of all registered .nl domains. The high level of DNSSEC support in the Netherlands is of course relevant in that context, since the use of DANE depends on DNSSEC being supported.

Line graph of stats.sidnlabs.nl showing the application of DANE in the .nl domain

Figure 1: The number of .nl domain names with DANE support. (Source: stats.sidnlabs.nl)

Configuring DANE

For anyone interested in securing mail domains and systems with DANE, we've published detailed advice on configuring DANE for both Postfix and Exim. If you need to set up DNSSEC first, we also provide a series of hands-on articles for the most popular DNS servers.

Other useful resources include our E-mail Standards Checklist and Maturity Model for Modern Internet Standards'.