Advanced Email Trust
What sits on top of authentication: MTA-STS and DANE for transport, TLS-RPT for evidence, BIMI for the inbox, and the deliverability signals no DNS record can buy.
- lessons
- 20
- total
- 4 h
- level
- Advanced
Assumes DMARC Practitioner.
You will be able to
- Explain what an attacker can do to opportunistic TLS, and what stops it
- Deploy and change an MTA-STS policy without losing mail
- Read a TLS report and name the failure it describes
- Read a TLSA record, and say when DANE is available to a domain at all
- Choose between DANE and MTA-STS, or justify running both
- State what BIMI requires, what it costs, and what it does not prove
- Separate the deliverability problems authentication solves from the ones it cannot
Syllabus
1. The Transport Problem
What an attacker does to opportunistic TLS, and the two answers the industry built.
2. MTA-STS
The three pieces, reading a live policy, and changing one without losing mail.
3. TLS Reporting
What the reports contain, and naming a failure from the type it carries.
4. DANE
TLSA records, the DNSSEC dependency that decides availability, and choosing between the two.
5. BIMI
What it requires, what the certificate costs, and what a logo does and does not prove.
6. Beyond Authentication
Forward-confirmed reverse DNS, complaint rates, and the bulk-sender requirements.
7. Adoption and Operation
The order to deploy in, what breaks, and what to watch once it is live.
8. Final assessment
15 scenario questions · 80% to pass · unlimited retakes
What the assessment covers
Advanced Email Trust
- Complete every lesson in Advanced Email Trust
- Pass the Advanced Email Trust assessment with at least 80%
CertaDNS Engineering · last reviewed