Article Details
Scrape Timestamp (UTC): 2024-07-17 19:04:53.809
Original Article Text
Click to Toggle View
Exchange Online adds Inbound DANE with DNSSEC for security boost. Microsoft is rolling out inbound SMTP DANE with DNSSEC for Exchange Online in public preview, a new capability to boost email integrity and security. As the Exchange team explained on Wednesday, DNS-based Authentication of Named Entities (DANE) for SMTP and Domain Name System Security Extensions (DNSSEC) work together to defend against downgrade and man-in-the-middle (MiTM) attacks. The SMTP DANE security protocol utilizes a TLS Authentication (TLSA) DNS record to verify the identity of destination mail servers and the authenticity of the certificates used for securing email communication. This ensures secure connections between sending and receiving servers and helps prevent TLS-downgrade attacks and MiTM attacks, where malicious actors monitor or alter communications. On the other hand, the DNSSEC DNS extensions provide cryptographic verification of DNS records during transit, preventing spoofing, hijacking, and interception of email messages. Once enabled in Exchange Online, Inbound SMTP DANE with DNSSEC will protect email domains from impersonation, ensure that messages are delivered to the intended recipients using encryption without being altered or redirected, and enhance email reputation through compliance with the latest security standards. The Exchange Team shared a rollout roadmap which says that the new capability will be deployed across all Outlook domains in late 2024: Microsoft will provide this new capability to enterprise and home customers for free and says it's already enabled for some Outlook domains. "We urge other email providers and domain owners to adopt these standards and collectively raise the bar for email security and protect users from malicious actors," the Exchange Team said. "We have already implemented inbound SMTP DANE with DNSSEC for several Outlook email domains, and we will complete the implementation for remaining Outlook domains (including Hotmail) by the end of 2024." After this new capability goes live, Microsoft will complete Exchange Online's support for SMTP DANE with DNSSEC since outbound SMTP DANE with DNSSEC has been supported since March 2022. The company initially announced in September 2023 that this public preview would roll out from March to July 2024. However, it was forced to delay it because of "necessary security investments" identified during the Private Preview stage.
Daily Brief Summary
Microsoft is introducing inbound SMTP DANE and DNSSEC in a public preview for Exchange Online to increase email security and integrity.
These security protocols are designed to prevent downgrade and man-in-the-middle (MiTM) attacks by authenticating mail servers and validating TLS certificates.
SMTP DANE uses a TLS Authentication (TLSA) DNS record for ensuring secure connections and verifying the identity of destination mail servers.
DNSSEC extension offers cryptographic verification of DNS records to prevent spoofing, hijacking, and interception during email transit.
The implementation aims to protect email domains from impersonation, ensure encryption-based delivery to the correct recipients, and boost email reputation.
Microsoft plans to deploy this feature across all Outlook domains by late 2024, already enabled for some domains, and available to enterprise and home customers for free.
The Exchange Team encourages other email providers and domain owners to adopt these standards to improve overall email security and safeguard against malicious activities.