Skip to main content

BSI Hall of Fame 2026: DNSSEC independently verified at mailbox

Having already been awarded BSI Gold status in the 2025 Email Security Year, mailbox is once again being inducted into the Hall of Fame this year: In 2026, the Federal Office for Information Security (BSI), eco – Association of the Internet Industry e. V. and Bitkom e. V. focused on the implementation of the DNSSEC email security standard. The BSI assessed participating companies on the successful implementation of these standards.

mailbox has been successfully implementing DNSSEC and other modern security standards for years, which makes us all the more delighted to have received this independent assessment and confirmation from the BSI. We are therefore among the companies that demonstrably offer their customers and staff a secure email infrastructure, as well as implementing and maintaining specific email security measures to improve online protection.

Trophy in recognition of excellent performance

Why is DNSSEC needed?

To understand DNSSEC and its benefits, it is worth taking a look at the basics of email communication: every time you send an email or visit a website, a query is made in the background. The reason for this is that whilst your device knows the name of the destination – such as mailbox.org – it does not know its technical address, which consists of a sequence of numbers. To find out this sequence of numbers, your device sends a query to a directory known as the Domain Name System (DNS).

This information forms the basis for everything that follows, as it is only with this that it is established which server your device is actually communicating with. However, DNS was designed at a time when trust in the internet was taken for granted. A response therefore carries no proof of who it actually originates from.

So anyone who intercepts the request can return a false address without your device having any way of detecting this. As a result, it would establish a connection to the wrong destination and your message would end up on a third-party server without you or your programme realising it.

What is DNSSEC?

DNSSEC stands for Domain Name System Security Extensions and closes the vulnerability described above. The idea behind it is a kind of digital seal. In the context of the example mailbox.org, this means: every response from our directory is cryptographically signed, much like a seal on a letter. Your device checks this seal before it uses the response. If it is intact, it is certain that the information actually comes from mailbox and that the seal has not been tampered with by anyone en route. If, on the other hand, it has been tampered with, the response is discarded and the connection is not established in the first place.

Nor can this seal be easily forged. It forms part of a chain that extends all the way back to the top level: the DNS root verifies the .org suffix, which in turn verifies our domain. Our domain, in turn, verifies the individual entries. In this way, each link vouches for the next.

DNSSEC when using your own domains

DNSSEC is implemented by default for mailbox domains. For a mailbox email address such as vorname.nachname@mailbox.org, you do not need to configure anything yourself. The DNS infrastructure for mailbox domains is operated and secured by mailbox.

 

For external domains, however, mailbox cannot control the DNS configuration required for DNSSEC. So if you use your custom domain with mailbox, you can set up and activate DNSSEC via your respective domain provider. The MX records can then continue to point to the mailbox mail servers, whose DNS information is in turn secured by mailbox.

Further security standards at mailbox

In addition to DNSSEC, mailbox utilises further comprehensive security standards for email, cloud and information security – including SSL/TLS, DANE/TLSA, MTA-STS, HSTS, CAA, CSP and X-XSS, SPF, DKIM and DMARC, as well as end-to-end encryption with PGP and S/MIME.

Compliance with high security requirements is ensured, amongst other things, by ISO/IEC 27001 certification, the BSI C5 certificate and the BSI IT Security Label. In addition to the BSI Gold status for email security, these certifications are complemented by the ‘Software Made in Germany’ quality mark and ‘Software Hosted in Germany’, as well as the European ‘Cybersecurity Made in Europe’ label.

mailbox Note 1,8 bei Stiftung Warentest
BSI C5 Type 1 Testat
ISO/IEC 27001:2022 Zertifikat
Cybersecurity Made in Europe
Quality label: Software hosted in Germany 2026
SMiG Quality label 2026

Give mailbox a go and benefit from independently verified email security!

mailbox erhält die Note 1,8 bei Stiftung Warentest

More news

mailbox erhält die Note 1,8 bei Stiftung Warentest

Stiftung Warentest reviews email providers and recommends mailbox

Read more about Stiftung Warentest reviews email providers and recommends mailbox
mailbox EVAC Smart Country Convention 2026

Staying operational when IT systems go down: EVAC at SCCON 2026

Read more about Staying operational when IT systems go down: EVAC at SCCON 2026
Produktupdate

Two new features for your day-to-day business

Read more about Two new features for your day-to-day business