USENIX Security2022Top-tier venue
Under the Hood of DANE Mismanagement in SMTP
Hyeonmin Lee, Md. Ishtiaq Ashiq, Moritz Müller, Roland van Rijswijk-Deij, Ted Taekyoung Kwon, Taejoong Chung
Abstract
The DNS-based Authentication of Named Entities (DANE) is an Internet security protocol that enables a TLS connection without relying on trusted third parties like CAs by introducing a new DNS record type, TLSA. DANE leverages DNSSEC PKI to provide the integrity and authenticity of TLSA records. As DANE can solve security challenges in SMTP, such as STARTTLS downgrade attacks and receiver authentication, it has been increasingly deployed surpassing more than 1 M domains with SMTP servers that have TLSA records. A recent study, however, reported that there are prevalent misconfigurations on DANE SMTP servers, which hinders DANE from being proliferated. In this paper, we investigate the reasons why it is hard to deploy and manage DANE correctly. Our study uses largescale, longitudinal measurements to study DANE adoption and management, coupled with a survey of DANE operators, some of which serve more than 100 K domains. Overall, we find that keeping the TLSA records from a name server and certificates from an SMTP server synchronized is not straightforward even when the same entity manages the two servers. Furthermore, many of the certificates are configured to be reissued automatically, which may result in invalid TLSA records. From surveying 39 mail server operators, we also learn that the majority keeps using CA-issued certificates, despite this no longer being required with DANE, since they are worried about their certificates not being trusted by clients that have not deployed DANE. Having identified several operational challenges for correct DANE management, we release automated tools and shed light on unsolved challenges.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e04a563e-eb65-49a5-93ac-82ae4fa1cb76Cited by top-tier papers7
- FakeBehalf: Imperceptible Email Spoofing Attacks against the Delegation Mechanism in Email SystemsJinrui Ma, Lutong Chen, Kaiping Xue, Bo Luo et al.USENIX Security 2024 · 7 citations
- Unfiltered: Measuring Cloud-based Email Filtering BypassesSumanth Rao, Enze Liu, Grant Ho, Geoffrey M. Voelker et al.WWW 2024 · 1 citation
- ExpressPQDelivery: Toward Efficient and Immediately Deployable Post-Quantum Key Delivery for Web-of-ThingsJane Kim, Jung-Hun Kang, Hyunwoo Lee, Seung-Hyun SeoWWW 2025 · 1 citation
- A Multifaceted Study on the Use of TLS and Auto-detect in Email EcosystemsKa Fun Tang, Che Wei Tu, Sui Ling Angela Mak, Sze Yiu ChauNDSS 2025
- You've Got Report: Measurement and Security Implications of DMARC ReportingMd. Ishtiaq Ashiq, Weitong Li, Tobias Fiebig, Taejoong ChungUSENIX Security 2023
Builds on3
- A Longitudinal, End-to-End View of the DNSSEC EcosystemTaejoong Chung, Roland van Rijswijk-Deij, Balakrishnan Chandrasekaran, David R. Choffnes et al.USENIX Security 2017 · 125 citations
- TLS in the Wild: An Internet-wide Analysis of TLS-based Protocols for Electronic CommunicationRalph Holz, Johanna Amann, Olivier Mehani, Mohamed Ali Kâafar et al.NDSS 2016 · 117 citations
- A Longitudinal and Comprehensive Study of the DANE Ecosystem in EmailHyeonmin Lee, Aniketh Gireesh, Roland van Rijswijk-Deij, Taekyoung Kwon et al.USENIX Security 2020
Related papers
- Extended Hell(o): A Comprehensive Large-Scale Study on Email Confidentiality and Integrity Mechanisms in the WildBirk Blechschmidt, Ben StockUSENIX Security 2023
- A Large-scale and Longitudinal Measurement Study of DKIM DeploymentChuhan Wang, Kaiwen Shen, Minglei Guo, Yuxuan Zhao et al.USENIX Security 2022
- Transparent Attested DNS for Confidential Computing ServicesAntoine Delignat-Lavaud, Cédric Fournet, Kapil Vaswani, Manuel Costa et al.USENIX Security 2025
- All Your DNS Records Point to Us: Understanding the Security Threats of Dangling DNS RecordsDaiping Liu, Shuai Hao, Haining WangCCS 2016 · 91 citations
- RHINE: Robust and High-performance Internet Naming with E2E AuthenticityHuayi Duan, Rubén Fischer, Jie Lou, Si Liu et al.NSDI 2023 · 12 citations
