Re: [Uta] NEWSFLASH: DANE TLSA records published for web.de!

Viktor Dukhovni <ietf-dane@dukhovni.org> Thu, 21 April 2016 16:17 UTC

Return-Path: <ietf-dane@dukhovni.org>
X-Original-To: uta@ietfa.amsl.com
Delivered-To: uta@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EE72E12DAA9; Thu, 21 Apr 2016 09:17:38 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CGGS1JKiyVrV; Thu, 21 Apr 2016 09:17:37 -0700 (PDT)
Received: from mournblade.imrryr.org (mournblade.imrryr.org [38.117.134.19]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5B57712E082; Thu, 21 Apr 2016 09:17:36 -0700 (PDT)
Received: by mournblade.imrryr.org (Postfix, from userid 1034) id 1AE41284951; Thu, 21 Apr 2016 16:17:35 +0000 (UTC)
Date: Thu, 21 Apr 2016 16:17:35 +0000
From: Viktor Dukhovni <ietf-dane@dukhovni.org>
To: uta@ietf.org, dane@ietf.org
Message-ID: <20160421161734.GO26423@mournblade.imrryr.org>
References: <20160414183856.GL26423@mournblade.imrryr.org>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <20160414183856.GL26423@mournblade.imrryr.org>
User-Agent: Mutt/1.5.24 (2015-08-30)
Archived-At: <http://mailarchive.ietf.org/arch/msg/uta/HytpLw1HTuMnsBSnyfFx9ooLrQo>
Subject: Re: [Uta] NEWSFLASH: DANE TLSA records published for web.de!
X-BeenThere: uta@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
Reply-To: uta@ietf.org
List-Id: UTA working group mailing list <uta.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/uta>, <mailto:uta-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/uta/>
List-Post: <mailto:uta@ietf.org>
List-Help: <mailto:uta-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/uta>, <mailto:uta-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 21 Apr 2016 16:17:39 -0000

On Thu, Apr 14, 2016 at 06:38:56PM +0000, Viktor Dukhovni wrote:

> The web.de domain has just published DANE TLSA records for its MX
> hosts.

And today also the rest of the major 1&1 (Mail&Media) email domains:

    gmx.de
    gmx.net
    gmx.com
    gmx.ch
    gmx.at

> This is a major milestone in DANE adoption.  [ IIRC they host
> mailboxes for a substantial fraction of the population of Germany. ]

    https://icannwiki.com/.gmx

    With over 32 million customers Mail&Media covers nearly 50% of
    the German Webmail market. With its brands, Mail&Media is the
    largest free email provider in the German speaking countries
    of Germany, Switzerland, Austria, Luxembourg and Liechtenstein.

Together with web.de this likely makes over 30 million recently
added mailboxes with DANE TLSA records.  DANE is now supported by
the below home internet / email / hosting  providers.

    gmx.at
    gmx.ch
    gmx.com
    mail.com
    gmx.de
    posteo.de
    unitymedia.de
    web.de
    comcast.net
    gmx.net
    t-2.net
    xs4all.net
    xs4all.nl
    transip.nl
    udmedia.de
    nederhost.net

DANE is no longer just at hobbyist domains and a few smaller early
adopters like Posteo and Unitymedia.  This is starting to get
interesting.

While the even larger Gmail, Outlook.com/Hotmail, Yahoo ... are
not in the near term in a position to deploy DNSSEC, I expect that
doing so is simpler for outlook.com, because this domain does not
overlap with major web properties whose scale makes the transition
considerably more difficult.  So it would be great to add Microsoft
to the above list some time in 2017 (or sooner).

DANE for gmail.com is also plausible without impacting all of
Google, but requires moving the MX hosts out of the present
google.com.

-- 
	Viktor.