frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Announce: SMTP DANE Verify – self-monitor your DANE policy

https://github.com/sys4/smtp-dane-verify
2•lquidfire•2h ago

Comments

lquidfire•2h ago
Mail server admins might (will? should?) have heard of DANE. DANE (DNS-based Authentication of Named Entities) and DNSSEC (Domain Name System Security Extensions) are complementary security protocols that work together to secure internet communications, especially email.

In the hopes of bringing more awareness to DANE, and how to implement (and monitor, which is key!) DANE on large and small mail servers, the friendly folks at sys4.de have published a tool to help monitoring DANE.

May DANE spread far and wide - and may your self-signed certificates be verified and trusted via your DNSSEC-authenticated DNS records!

From a post by Patrick Ben Koetter to the DANE mailing list at sys4.de [0]:

Greetings!

Our this year's Christmas gift to the community is a service that let’s you monitor and detect typical DANE related problems for DANE-enabled inbound SMTP services. You can integrate the service in your own service environment or run it as a docker container and poll it for test results from a monitoring service.

## Why? We believe every platform should enable and use DANE. DANE is the missing piece in TLS or as Wietse Venema once put it: „Encryption without authentication is not 'security'. It just gives some privacy.“ DANE adds the missing authentication bit. But DANE enforces strict policy and if your platform fails inbound DANE-verification you will not receive email from those platforms that enforce outbound DANE-verification. A failing DANE policy imposes a production risk.

## Why would your platform fail DANE verification? From discussions with Viktor about the statistics he generates at https://stats.dnssec-tools.org/#/ we know that in most cases, when DANE-enabled platforms fail DANE-verification, it is because the published TLSA resource record(s) in DNS do not match one of the x509 certificate's fingerprint.

We want everybody to benefit from the security DANE adds to TLS and not have people look at it as a production risk! This is why we built the SMTP DANE Verify service. It will test and detect common DANE policy problems. Using SMTP DANE Verify everybody will be able to monitor their own (and other) domains and raise an alarm in case the tested domain fails DANE verification.

## How would you use SMTP DANE Verify? If you think SMTP DANE Verify is for you check out the project at https://github.com/sys4/smtp-dane-verify. The project's README should give you all the information you need to setup, run and integrate SMTP DANE Verify on your platform.

On a sidenote: In case you are still in doubt if anyone should be using DANE at all: the EU has launched a Multi-Stakeholder Working Group for Internet Standards in the EU and DANE is a major item on the groups roadmap. Follow this link to read more: https://digital-strategy.ec.europa.eu/en/news/european-commi......

And that's it! We hope you will find it as useful as we do. Season greetings to all of you. Peace on earth to all of us. o:)

p@rick

[0]: https://list.sys4.de/hyperkitty/list/dane-users@list.sys4.de...

Hollywood cozied up to AI in 2025 and had nothing good to show for it

https://www.theverge.com/ai-artificial-intelligence/848119/hollywood-film-tv-ai-2025
1•MilnerRoute•38s ago•0 comments

Calorie Restriction Attenuates Aging Signatures in White Matter Oligodendrocytes

https://onlinelibrary.wiley.com/doi/10.1111/acel.70298
1•PaulHoule•3m ago•0 comments

Tinykit: Self-hosted Lovable/v0 alternative. Realtime database, storage included

https://github.com/tinykit-studio/tinykit
1•thunderbong•3m ago•0 comments

Show HN: Web CLI – Browser-based terminal with multi-tab support

https://github.com/pozgo/web-cli
1•polinux•3m ago•0 comments

Achieving 1.2 TB/s Aggregate Bandwidth by Optimizing Distributed Cache Network

https://juicefs.com/en/blog/engineering/terabyte-aggregate-bandwidth-distributed-cache-network
1•LittleCat38•6m ago•0 comments

Serious Memory Series

https://pwnosaur.com/
1•0xkato•7m ago•0 comments

Neuromorphic Software Guide

https://open-neuromorphic.org/neuromorphic-computing/software/
2•ArmageddonIt•7m ago•0 comments

The Renewable-Energy Superpower

https://www.economist.com/special-report/2025/11/03/the-worlds-renewable-energy-superpower
2•karakoram•11m ago•1 comments

Why does software still take years to ship when months should be enough?

1•saichler•13m ago•0 comments

The /Do Router: Keyword Matching for Specialist Selection in Claude Code

https://vexjoy.com/posts/the-do-router/
2•AndyNemmity•15m ago•1 comments

As A.I. Companies Borrow Billions, Debt Investors Grow Wary

https://www.nytimes.com/2025/12/26/business/ai-debt-investors.html
2•pseudolus•17m ago•2 comments

Show HN: Aegis Memory – Open-source memory layer for multi-agent AI systems

https://github.com/quantifylabs/aegis-memory
1•Arulnidhi_k•17m ago•0 comments

iPhone Air 2 Could Still Launch Next Year

https://www.macrumors.com/2025/12/24/iphone-air-2-could-still-launch-next-year/
1•appsDev•19m ago•1 comments

I flew inside my phone – The Hidden City [video]

https://www.youtube.com/watch?v=QtW1lQITckE
1•Group_B•20m ago•0 comments

Books I Read in 2025

https://arslan.io/2025/12/26/books-i-read-in-2025/
1•farslan•28m ago•0 comments

Publisher Pathfinder: a tool to help developers find publishing partners

https://www.gamesindustry.biz/publisher-pathfinder-is-a-new-tool-to-help-developers-find-publishi...
2•ohjeez•30m ago•0 comments

Show HN: AutoLISP interpreter in Rust/WASM – a CAD workflow invented 33 yrs ago

https://acadlisp.de/noscript.html
5•holg•30m ago•4 comments

Show HN: Private blogging and journaling with a simulated audience

https://tempblog-psi.vercel.app/
3•beerd•32m ago•3 comments

Show HN: A schema-first, multi-agent pipeline for autonomous research

https://github.com/giatenica/gia-agentic-short
2•7777777phil•35m ago•0 comments

The Quest of the Simple Life

https://collabfund.substack.com/p/the-quest-of-the-simple-life
1•RickJWagner•35m ago•0 comments

Building Trust Online

https://www.trustengine.quest/
1•AgustinRhetoric•36m ago•1 comments

Switching my website from Hugo to Quarto

https://nrennie.rbind.io/blog/hugo-quarto-website/
1•m-hodges•36m ago•0 comments

Bash script to vendor in NPM packages to your repo

https://gist.github.com/danthegoodman1/021678f0aac498d7d644a70609109655
2•dangoodmanUT•39m ago•1 comments

Open Neuromorphic

https://open-neuromorphic.org
2•bcye•39m ago•0 comments

UK campaigner targeted by Trump accuses tech giants of 'sociopathic greed'

https://www.theguardian.com/us-news/2025/dec/26/uk-campaigner-targeted-by-trump-accuses-tech-gian...
4•pera•41m ago•1 comments

From Intent to Proof: Dafny Verification for Web Apps

https://midspiral.com/blog/from-intent-to-proof-dafny-verification-for-web-apps/
2•namin•42m ago•0 comments

Bypass Windows user interface privilege isolation via the CTF input method proto

https://projectzero.google/2019/08/down-rabbit-hole.html
1•fanf2•45m ago•0 comments

Find Your Celebrity Twin with AI

https://celeblookalike.org/
1•ivanvolt•48m ago•0 comments

I shrunk down into an M5 chip [video]

https://www.youtube.com/watch?v=Jh9pFp1oM7E
2•Timothee•49m ago•1 comments

Show HN: Hybrid-Transpiler – A tool to convert C++ to Rust and Go

https://github.com/cmc-labo/hybrid-transpiler
2•hpscript•49m ago•1 comments