The Internet Engineering Task Force (IETF) is developing a new DNS protocol called DANE, which will be experimental. The new protocol will be able to hide email addresses in DNS records.
DANE, or DNS-Based Authentication of Named Entities, is a new protocol originally developed to allow TLS/SSL certificates to be associated with DNS records that use DNSSEC (Domain Name System Security Extensions).
When it was first introduced, DANE was supposed to help browsers verify whether a TLS/SSL certificate contained a valid CA certificate by checking a special field in the DNS record.
The protocol, which is still in an experimental stage and under continuous development by the IETF, appears to add an additional privacy feature that will allow domain providers to hide email addresses.
As the Register reports, the IETF team has decided to add this feature to the DANE protocol roadmap, which means that once it is released, email addresses will appear in hashed (encrypted) form in DNS record results.
This reduces the chances of domain hijacking since it will not display an email address in plain text to the attacker.
It should be noted that the hashed email message can still be hacked and reveal the real email, but the attacker would have to have the skills and knowledge to do so. So the new protocol adds another layer of security to our privacy.
But we will have to wait for the development and testing to be completed.
