Running a mail server is hard work.
Keeping up with requirements to participate in the federated mail-universe is a burden.
You have to use DNSSEC, DANE, DMARC, SPF, DKIM, good ciphers for TLS, IPv6, ...
Today I have configured CAA [0] records and added intermediate certificates from letsencrypt for DANE [1] in the DNS.
[0] https://en.wikipedia.org/wiki/DNS_Certification_Authority_Authorization
[1] https://letsencrypt.org/certificates/#subordinate-intermediate-cas











