RFC 7672 · PROPOSED STANDARD · 2015

SMTP Security via Opportunistic DNS-Based Authentication of Named Entities Transport Layer Security

Overview

RFC 7672, “SMTP Security via Opportunistic DNS-Based Authentication of Named Entities Transport Layer Security”, is a Proposed Standard document published in October 2015 by V. Dukhovni, W. Hardaker. The canonical text is published by the RFC Editor.

Abstract

This memo describes a downgrade-resistant protocol for SMTP transport security between Message Transfer Agents (MTAs), based on the DNS-Based Authentication of Named Entities (DANE) TLSA DNS record. Adoption of this protocol enables an incremental transition of the Internet email backbone to one using encrypted and authenticated Transport Layer Security (TLS).

Abstract as published in the RFC, via rfc-editor.org.

What “Proposed Standard” means

An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.

Read this RFC

The canonical text of RFC 7672 is hosted at rfc-editor.org. Available in TXT,HTML.

Other RFCs from 2015

Who Is Online

In total there are 119 users online: 0 registered, 113 guests and 6 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: AhrefsBot Bingbot Other Bot Other Crawler PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 372