Hello Proofpoint!
Cloudflare, Microsoft, Trend Micro Europe, Mimecast and many others support DNSSEC + DANE. You do not, and I just cannot understand why!
In fact, when searching your website, it looks like the only place you mention DNSSEC is in your glossary about Domain Spoofing. It says “Domain Name System Security Extensions (DNSSEC) provide an added layer of security to the DNS by using cryptography to write DNS records. This makes it significantly more difficult for fraudsters to manipulate DNS records and redirect users to malicious websites, ensuring the integrity and authenticity of DNS responses.”
This is true, but still you do not use or support it yourselves. Why not?
As a consultant, but even more as a person who deeply believes in implementing Internet standards for improving security & privacy for everyone, I do not understand why you still do not support these standards. I see you bragging about your placement in the Gartner magic quadrant at https://www.proofpoint.com/us/resources/analyst-reports/gartner-magic-quadrant-for-email-security, which makes me think that either Gartner is “way off” in their security evaluations, or at least you are with your apparent lack of supporting internet security standards for DNS (DNSSEC) & Email (DANE).
A few hints to make you reconsider supporting existing standards, for which there are no alternatives:
- The Dutch government doesn’t require these standards, but they do require a “PhD level” risk analysis from you if you choose NOT to support these standards.
- The Danish government require ALL of public sector to use DNSSEC + DANE, no exceptions, period. Meaning none of them can use Proofpoint! See my Linkedin article about email security at Danish law firms for more info.
- The Norwegian government has recommended DNSSEC + DANE for years. Although still only a recommendation, trust me, I’m pushing everyone I can to make it a requirement.
- EU has, AFAIK, started work that might make DNSSEC + DANE mandatory across all of EU. That’s a pretty big market for you I would guess. Protip: do it, or get out.
Using the excellent free service of Dutch Internet Standards Platform (Internet.nl) , I checked your own proofpoint.com domain to verify your lack of these standards for your own domain as well:
It seems to me though that you launched support for MTA-STS (RFC 8461) back in 2019, but a quick test shows you are not using it yourselves, not even in test mode. Doesn’t increase confidence, does it?
So please Proofpoint, look into implementing support for DNSSEC + DANE as soon as possible. Or get lost. imho.
Originally published on LinkedIn.

