Category
Email security
Topic
Email Security in 2025 – Glossary
Audience
Businesses & IT managers
Reading time
approx. 5 minutes

To mark the Year of Email Security 2025, Mint Secure is publishing a brief guide to email security terminology. Mint Secure has been inducted into the ‘Hall of Fame’ for email security topic by the Federal Office for Information Security (BSI), as it itself meets the relevant standards. Furthermore, Mint Secure supports customers in setting up secure email configurations, thereby making an important contribution to email security in Germany.

The following terms are particularly relevant when dealing with email security:

Sender authenticity: DKIM, SPF & DMARC

DKIM – “Yes, this email really is from the company.”

DKIM (Domain Keys Identified Mail) makes it more difficult to send Phishing emails with forged sender addresses. If an email is signed with DKIM, the recipient can unambiguously associate it with the sender’s domain. The keys used for the signature are stored in the DNS (Domain Name System).

SPF – “Only authorised servers may send emails on my behalf.”

With an SPF record in the DNS, domains specify which mail servers have permission to send their emails. This allows receiving servers to check whether an incoming email actually originates from an authorised sender.

DMARC – “Anyone sending emails in my name without authorisation will be reported or blocked.”

A DMARC policy specifies how receiving mail servers should handle messages sent on behalf of a domain but which fail the SPF or DKIM checks. The options range from simply logging the incident and informing the domain owner to flagging such emails as spam or rejecting them outright. DMARC only achieves its full effect when used in combination with SPF and DKIM. DMARC stands for Domain-based Message Authentication, Reporting, and Conformance.

Only the combined use of SPF, DKIM and DMARC provides reliable protection against spoofed sender addresses; when used individually, these mechanisms offer only partial protection.

Encrypted transmission & trust anchors: TLS, DANE, DNSSEC & MTA-STS

TLS – “Let’s talk in code so nobody can eavesdrop.”

TLS (Transport Layer Security) is the standard for encrypted communication between mail servers. This ensures that emails are transmitted securely and protected against unauthorised access or tampering. It is important to use modern, secure encryption methods.

DANE – “I can cryptographically provide evidence of my identity.”

With DANE (DNS-based Authentication of Named Entities), a mail server can provide evidence that it communicates exclusively via encrypted channels. The keys used for this are bound to the domain and made verifiable via DNS. DNSSEC serves as the security anchor here.

DNSSEC – “No more fake redirects.”

DNSSEC (Domain Name System Security Extensions) ensures that the information stored in the DNS is complete and authentic. It protects users from attacks in which they are redirected to manipulated or malicious servers. As a strong anchor of trust, DNSSEC is a prerequisite for the use of DANE.

MTA-STS – “No delivery without encryption.”

MTA-STS (SMTP MTA Strict Transport Security) ensures that a mail server communicates exclusively via encrypted channels, similar to DANE. The difference is that, instead of DNSSEC, MTA-STS uses certificates as a security anchor. Whilst it does not quite achieve the same level of protection, it does not require DNSSEC.

Mint Secure in the BSI Hall of Fame

The definitions and descriptions are based on the document “Briefing Supplement – The Year of Email Security 2025”. Mint Secure was inducted into the ‘Hall of Fame’ alongside 150 other companies and presented with a certificate in recognition of its outstanding commitment to email security in Germany and its implementation of modern standards.

Foto zur Urkundenübergabe

How Mint Secure supports you

Setting up SPF, DKIM, DMARC, TLS, DANE, DNSSEC and MTA-STS in the right combination is complex; configuration errors often weaken protection without anyone noticing. We provide support with the following services:

✉️

Email security configuration

We professionally set up SPF, DKIM and DMARC for your domains and check existing configurations for vulnerabilities.

🔒

Transport encryption

We implement TLS, MTA-STS and DANE to ensure that emails are reliably encrypted when transmitted between mail servers.

🌐

DNSSEC setup

We provide support with the implementation of DNSSEC as a trust anchor for DANE and other DNS-based security mechanisms.

Want to get started? We offer a free initial consultation. Get in touch now.

Conclusion

DKIM, SPF and DMARC ensure the sender’s authenticity, whilst TLS, DANE and MTA-STS protect the transmission; DNSSEC acts as the trust anchor within the DNS. It is only when these standards work together that they achieve their full protective effect.

As a company recognised by the BSI and inducted into the Email Security Hall of Fame, Mint Secure consistently implements these standards itself.

We can also help you secure your email infrastructure using state-of-the-art technology. Get in touch with us.