I have enabled DNSSEC at the registrar, but had to remove their entry. They removed the signing 16 days ago (must enough time to be not cached by public DNS anymore), but third party mailserver (such as tutanota.com, posteo.de etc.) that are DANE-enabled mail servers do still x-check and see an entry, thus not delivering (because guess they assume MiaB is under attack). They recognize MiaB still supports DANE (cf. posteo).
_"Warning! TLSA records for _443.tcp.box.emailserver.com. were found, but were insecure. PKIX validation without DANE will be performed. If you wish to perform DANE even though the RR’s are insecure, use the -d option. Warning! Insecure IPv4 addresses. Continuing with them… 99.999.99.999 dane-validated successfully"
Can anyone jump in here? After the registrar removed the signing of my DNSSEC zone, ALL DANE-enabled mail servers still do think MiaB is using DNSSEC, and of course they can not verify (no signing anymore at registrar) so they look at mails from MiaB as compromised, so reject the mails coming from MiaB.
Any additional steps that needs to be taken to disable DNSSEC completely on MiaB? Thanks!