make DANE for email avaible
In Plesk 18.0.54, published July 18th, 2023, Plesk has added the ability to add Transport Layer Security Authentication (TLSA) DNS records to domains’ DNS zones in Plesk. Such records are most commonly used to implement DNS-based Authentication of Named Entities (DANE). With this update the most popular DANE scenario is covered in Plesk for Linux.
Now, with Plesk 18.0.56, published October 10th, 2023, the SSL It! extension supports DANE that ensures reliable encryption for email transport. When a Let’s Encrypt certificate is being issued, TLSA DNS records of email services will now automatically contain information about the certificate.
Please let us know your thoughts on this feature or whether you require additional functions.
-- PD
-
Iris Arnold commented
Please fix a.s.a.p. !!!!!!!!!!!!!!!
-
Henri Udding commented
This needs to be added asap. How can this not be implemented
-
Sjoerd Flonk commented
Dane is critical for our servers. No supports from plesk means for us exit!
-
Hans | Pixel Creation commented
This was one of the reasons we chose to never host any e-mail on our Plesk servers at all for any of our customers but only use services like Office 365 and Postmark. Such a shame.
-
Dr Gerard Bulger commented
This is becoming silly, the delay in implementing DANE on Plesk.
Currently I am not being blocked by the likes of Microsoft as SPF DKIM and DMARC are place. But the time is soon approaching. It's not surprising that Google and Microsoft want to strangle all email servers and force all on onto their systems on the grounds of "security". To protect PLESK market Plesk must implement DANE now, and prevent a dangerous duopoly
-
Divaldo Carlos commented
I have more then 100 clients and at this point we do have alot of problemas with email deliverability. Some providers just block us. I had to implement a dedicated server for emails, so you are loosing money without this feature.
-
Stefano Sabino commented
All my customers over 60 domain can no longer deliver email to outlook.com, http://rfc-clueless.org/ are blocked because the IN TLSA entry is missing, what's wrong with you guys from Plesk?
-
Anonymous commented
I am disappointed , Plesk has gotten a dent in it's image of almost perfection.
Unbelievable that this is not corrected;
All of us who try so hard to get mail delivered as it should, as if that is not already difficult enough! -
Andreas Schulz commented
For security reason tt's needed ASAP. That it isn't implemented is incomprehensible.
-
Ricky Rijsdijk commented
This needs to be added asap. How can this not be implemented
-
Martijn Koek commented
How many votes do you need exactly?
I agree with all people that state that this shouldn't be a voting, it just should be there.
We also had to change systems for some clients just to keep them as a client. Not fixing this will make Plesk lose all their (serious) clients. We are considering switching to another system if this is not going to be addressed!
-
Hans | Pixel Creation commented
"only raise prices" isn't fair. They've been doing a lot of updating and improving.
Problem is, this very basic and fundamental security feature hasn't had ANY priority for well over five years now.
As someone else stated: This is not a feature that should be considered given enough popular demand. It's a basic feature that should just be there.
-
Fany VanDaal commented
Plesk does not meet standards. Security should be a priority. Instead, they only raise prices, but do not listen to what their paying customers need in the long run to provide secure services.
-
Michiel Klaver commented
Microsoft published an Office365 message center notification MC308285 on December 24, to say that a slow roll-out of DANE and DNSSEC for outbound email will start in mid-January 2022 and complete by late May.
Since Office365 is by far the largest e-mail provider world-wide, this will have a huge impact.
-
Michiel Klaver commented
Adding TLSA DNS record support for DANE shoudn't be a feature to be added when it's deemed 'popular' enough, as the description states. This is a fundamental basic security setting that should have been included long ago.
There's clear demand from the market, including a lot of your very own customers, competitors are offering it for ages, and various governments and security baselines require DANE to be active.
Again, stop treating this as some minor nice-to-have feature request and add it with priority to your upcoming sprint, as it's highly overdue.
-
Anonymous commented
This NEEDS to be supported in order to comply with some countries regulatory requirements.
-
Weare Borg commented
@Gijsbert it is very embarrassing even free control panels are offering it.
-
Gijsbert Schrijvers commented
Still no TLSA for Dane... It is almost embarrassing to tell my customers that a big company as Plesk does not support it.
Some customers are asking for this for years now. I need to switch to an other system that does support this option. It is a shame that a security feature is not yet implemented after the first post in 2016.
Some customers need this as a request from governments, or IT auditors. I can't keep telling them it is not possible.
-
Arno Visser commented
Please add DANE in the plesk functionality. It becomes more and more required for security badges. I would really like to see Plesk support for DANE and TSLA.
-
Hans | Pixel Creation commented
I'm having to tell our customers we can't offer something that our competitors do. Please make this a priority.