make DANE for email avaible
In Plesk 18.0.54, published July 18th, 2023, Plesk has added the ability to add Transport Layer Security Authentication (TLSA) DNS records to domains’ DNS zones in Plesk. Such records are most commonly used to implement DNS-based Authentication of Named Entities (DANE). With this update the most popular DANE scenario is covered in Plesk for Linux.
Now, with Plesk 18.0.56, published October 10th, 2023, the SSL It! extension supports DANE that ensures reliable encryption for email transport. When a Let’s Encrypt certificate is being issued, TLSA DNS records of email services will now automatically contain information about the certificate.
Please let us know your thoughts on this feature or whether you require additional functions.
-- PD
-
Moritz Witte commented
Nice feature, is there an option to use reuse_key = True?
-
Anonymous commented
7 years until , unbelievable....
-
RNLDNKP commented
That's nice progress!
Please also integrate this with SSL IT/Lets Encrypt. Or at least make sure "reuse_key = True" can be set using panel.ini
-
Recently, some users have asked when this feature can be expected. A specific date may raise false expectations, so we do not want to guarantee a delivery date at this time. Unexpected obstacles may arise during development. Other urgent updates to other components that cannot wait for security reasons may affect development. Therefore, any date given can only be a rough estimate.
Plesk is currently developing this feature. We expect to deliver part of the components by August 2023 and a final version for all operating systems and versions supported by Plesk by the end of Q3/2023 - subject to change for the reasons stated above.
-- PD -
Hans | Pixel Creation commented
Could you give us an indication of when we can expect this? Is this something coming in the coming weeks? Months? Next year?
-
Quentin Seither commented
Whaouuuuhhhhh impossibles ! Its à joke !
-
Klaus-Uwe Mitterer commented
The fact that this is *still* not implemented is one of the reasons why, over the coming months, we will migrate away from Plesk. This is just absurd.
-
Weare Borg commented
After 7 year you might think that this would have been implemented. Can it be that some providers block you because of this.
-
Thomas Faßbender commented
Please make it Real, its Nessesary, that Global Mailserver will accept the Mailserver
-
David Toribio commented
· Oct 25, 2016 ???
-
Weare Borg commented
In 7 months this will be 7 years old and still implementation in Plesk. The saddest part is that open source control panels have this feature.
-
Marcel Oerlemans commented
Please add this function, would be great to see this implemented in Plesk.
-
Anonymous commented
Why has this not been added yet? This is required to be in line with industry standards.
-
Pieter Waegeman commented
Please add this.
-
Anonymous commented
hurry up Plesk, time to implement this, it 2 *past* 12...
-
Jonas commented
Please add this. It is necessary for me and my customers!
-
Weare Borg commented
It would be great if we got a fully hardened email setup. So that domains on the server can do email champagnes without the risk of being seen as spammers. First if you cant get 100% at https://en.internet.nl/ its an automatic fail. Second take a clue from https://mailinabox.email/ how to guide people and setup the mail server. You are taken by the hand and guided all the way. Plesk and mail are the worst you can have no DANE yet after 6 years of asking. This needs to be updated asap else domains on plesk will get blacklisted for not having setup to industry standards.
-
Weare Borg commented
Almost 6 years old and still nothing, the silence is deafening.
-
Klaus-Uwe Mitterer commented
As so many people have said before, this is absolutely critical. When is DANE coming to Plesk?
-
Dr Gerard Bulger commented
Yes it WILL be popular. Delivery of email from VPS and other Plesk servers is becoming more and more problematic while Microsoft and Google impose their monopoly on email services on the Grounds of "security" Once on these companies secret blacklists (often because somebody else in the network block has been a bad actor) it can take weeks to be removed.
DANE now essential, alone with DKIM, DMARC, SPF.