Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[enhancement]: Remove technical subdomains from default MX patterns for MTA-STS #429

Closed
1 task done
yannikbloscheck opened this issue May 14, 2024 · 2 comments
Closed
1 task done
Labels
enhancement New feature or request

Comments

@yannikbloscheck
Copy link

Which feature or improvement would you like to request?

The default MX patterns used by the MTA-STS get created from the available TLS certificates, but there is one problem with it:
I also need to use TLS certificates for the CNAME entries of mta-sts.example.com, autoconfig.example.com and autodiscover.example.com. So I added those to the ACME provider. Therefore by default they also appear in the mta-sts.txt as MX entries.
For now I just used the MX patterns override field and that of course works.
It might be a good idea though to automatically exclude entries starting with mta-sts., autoconfig. or autodiscover. from that default list.

Is your feature request related to a problem?

No response

Code of Conduct

  • I agree to follow this project's Code of Conduct
@yannikbloscheck yannikbloscheck added the enhancement New feature or request label May 14, 2024
@yannikbloscheck
Copy link
Author

Probably also better remove technical subdomains from the TSLA records

@marcoxyz123
Copy link

The TLSA records should reflect the correct port what they are used for, in this case "443". The missing TLSA records for IMAPS and SMTPs should be added to.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants