Internet Technologies 2 November 2016

NIST Publishes New Guide: “DNS-Based Email Security” about DANE and DNSSEC

By Dan YorkSenior Director, Online Trust and Safety
NIST Report on DANE for email

How can we make email more secure and trusted? How can we encrypt all email between mail servers? And how can we use DANE and DNSSEC to provide that added layer of security?

Today the U.S. National Cybersecurity Center of Excellence (NCCoE)  and the National Institute of Standards and Technology released a “draft practice guide” exploring those exact questions. Titled “Domain Name Systems-Based Electronic Mail Security (NIST Special Publication 1800-6)” the document offers guidance to enterprises and others into “how commercially available technologies can meet an organization’s needs to improve email security and defend against email-based attacks such as phishing and man-in-the-middle types of attacks.”  Specifically it gets into how DNSSEC and DANE can be used to authenticate server addresses and the Transport Layer Security (TLS) certificates used for confidentiality.

As NIST states on their web page, the goal of the project around this publication is:

  • Encrypt emails between mail servers
  • Allow individual email users to digitally sign and/or encrypt email messages
  • Allow email users to identify valid email senders as well as send digitally signed messages and validate signatures of received messages

You can download the guide or sections of it from that web page.

NIST is seeking public comments on this new guide from today through December 19, 2016.

It’s great to see NIST publishing this document and we hope everyone reading this post will take a look and spread the word.

And if you are interested in getting started with DNSSEC and DANE, please visit our Start Here page to find resources to help.

Disclaimer: Viewpoints expressed in this post are those of the author and may or may not reflect official Internet Society positions.

Related Posts

Open Internet Standards 21 May 2026

On Global Accessibility Awareness Day, An Internet for Everyone Must Include Everyone 

Today, 21 May, marks the 15th Global Accessibility Awareness Day (GAAD)–a day dedicated to getting everyone talking, thinking, and learning about...

Internet Policy 3 April 2026

DNS Blocking: Mind the Unintended Consequences

As DNS blocking mandates multiply, so do concerns about security, the openness of the Internet, and fragmentation.

Rebuilding Trust 16 January 2025

Today’s US Executive Order is a Serious Win for Cybersecurity

The United States government is taking a major leap forward for cybersecurity. The newly released Executive Order on Strengthening and...