> It already needs the best security it can possibly get.
It's just that I believe that DNSSEC should be part of the mix.
For instance here's an example of some research out of CERT-CC back in September 2014 where hijacking of MX records is redirecting email to someone:
http://www.internetsociety.org/deploy360/blog/2014/09/email-...
As far as I can see, deploying DNSSEC validation on the networks of the affected mail servers - and receiving DNSSEC-signed MX records - would prevent them from delivering mail to servers in the middle.
It's things like this that I want to prevent.
I want a more secure Internet - and in my view DNSSEC helps.