diff --git a/static/features.html b/static/features.html
index 12407b64..44633f19 100644
--- a/static/features.html
+++ b/static/features.html
@@ -211,10 +211,13 @@
Strong cipher configurations for all of our services (SSH, TLS, etc.) with
only modern AEAD ciphers providing forward secrecy
Our web services use OCSP stapling with Must-Staple
- DNSSEC implemented for all of our domains, which is particularly important
- for securing email due to it relying on DNS records
- DANE TLSA records for pinning keys for all our TLS services (mostly helps
- to secure email due to lack of browser support)
+ DNSSEC implemented for all of our domains
+ DNS Certification Authority Authorization (CAA) records for all of our
+ domains permitting only Let's Encrypt to issue certificates with fully
+ integrated support for the experimental accounturi
and
+ validationmethods
pinning our Let's Encrypt accounts as the only ones
+ allowed to issue certificates
+ DANE TLSA records for pinning keys for all our TLS services
Our mail server enforces DNSSEC/DANE to provide authenticated encryption
when sending mail including alert messages from the attestation service
SSHFP across all domains for pinning SSH keys