mirror of
https://github.com/mailscope/kumomta.git
synced 2026-08-19 10:58:17 +00:00
dfb17abd0d
Per RFC 7672 section 2.2.2, an MX host that is a securely published CNAME remains DANE-eligible at its original name even when the alias target lands in an unsigned zone: it is the secure TLSA RRset, not the address records, that authenticates the peer. When the address chain is insecure but MX selection was secure, an explicit CNAME query isolates the alias's own DNSSEC status; a secure alias engages DANE, an indeterminate status defers for downgrade resistance. refs: https://github.com/KumoCorp/kumomta/pull/545#discussion_r3472353021