simple-login / app

The SimpleLogin back-end and web app
https://simplelogin.io
GNU Affero General Public License v3.0
4.99k stars 420 forks source link

Add the same security measures to domains. #1209

Open c0nfigurati0n opened 2 years ago

c0nfigurati0n commented 2 years ago

@nguyenkims is it possible to also add DNSSEC, CAA records, MTA-STS, and TLS-RPT to the following domains?

jakob11git commented 2 years ago

I checked the current status for these domains right now.

Domain name DNSSEC CAA MTA-STS TLS-RPT
simplelogin.com
ale***.com
8sh****.net
8al***.com
dral***.com

Feels a bit all over the place. I agree with the OP that these generally might be good additions, and it would be nice to get the same uniform configuration regardless of domain name being chosen.

c0nfigurati0n commented 2 years ago

@jeifour agreed. A universal configuration would be nice.

Mello7sh3i commented 1 year ago
Domain name | DNSSEC | CAA | MTA-STS | TLS-RPT -- | -- | -- | -- | -- aleeas.com | ✅ | ✅ | ❌ | ❌ 8alias.com | ❌ | ❌ | ❌ | ❌ slmails.com | ❌ | ✅ | ❌ | ❌ silomails.com | ❌ | ✅ | ❌ | ❌ 8shield.net | ✅ | ✅ | ❌ | ❌ dralias.com | ❌ | ❌ | ❌ | ❌ slmail.me | ✅ | ✅ | ✅ | ✅ simplelogin.fr | ✅ | ✅ | ✅ | ✅ simplelogin.com | ✅ | ❌ | ❌ | ❌ simplelogin.co | ✅ | ✅ | ✅ | ✅ passmail.com | ❌ | ❌ | ❌ | ❌ passmail.net | ❌ | ❌ | ❌ | ❌

Update 1 year later, with the new domains. Today, only 3 out of 12 domains are fully configured, and 4 have nothing.

c0nfigurati0n commented 1 year ago

@Mello3vnik nice dox of the premium domains.🤦

Mello7sh3i commented 1 year ago

@Mello3vnik nice dox of the premium domains.🤦

and unfortunately, the same applies to the two domains used by protonpass... I will continue to update the table started above by yanagibashi-mt.

Honestly, it's very frustrating because it would only take an hour or two to finish everything. I can understand that the SL team is busy with other projects, but this is the core of the business that hasn't been completed.

Mello7sh3i commented 8 months ago
Domain name | DNSSEC | CAA | MTA-STS | TLS-RPT -- | -- | -- | -- | -- aleeas.com | ✅ | ❌ | ✅ | ✅ 8alias.com | ❌ | ❌ | ✅ | ✅ slmails.com | ❌ | ❌ | ✅ | ✅ silomails.com | ❌ | ❌ | ✅ | ✅ 8shield.net | ✅ | ❌ | ✅ | ✅ dralias.com | ❌ | ❌ | ✅ | ✅ slmail.me | ✅ | ❌ | ✅ | ✅ simplelogin.fr | ✅ | ❌ | ✅ | ✅ simplelogin.com | ✅ | ❌ | ✅ | ✅ simplelogin.co | ✅ | ✅ | ✅ | ✅ passmail.com | ❌ | ❌ | ✅ | ✅ passmail.net | ❌ | ❌ | ✅ | ✅

A few months later, a few changes : All domains are protected by MTA-STS, but only in testing mode. However, CAA records have disappeared. No progress on DNSSEC.