diff --git a/static/features.html b/static/features.html index 2f260035..44d1914d 100644 --- a/static/features.html +++ b/static/features.html @@ -194,6 +194,8 @@ for securing email due to it relying on DNS records
  • DANE TLSA records for pinning keys for all our TLS services (mostly helps to secure email due to lack of browser support)
  • +
  • Our mail server enforces DNSSEC/DANE to provide authenticated encryption + when sending mail including alert messages from the attestation service
  • SSHFP across all domains for pinning SSH keys
  • Static key pinning for our services in apps like Auditor
  • No cookies or similar client-side state for anything other than login sessions,