But is there any provider out there which supports DANE on outgoing email, ie. enforcing STARTTLS if the recipient domain requests so ?
(It seems governments and domain name registries love talking about DANE, but few actual email providers care to implement it)
Have you tested with a target SMTP server that is:
a. Properly configured for DANE
b. Misconfigured (eg. TLSA record conflicts what the server requires for TLS) to simulate MITM attack
c. Unconfigured to simulate downgrade attack
In essence, it seems simple enough that I would expect all larger providers to respect DANE, so I am curious what makes you think they aren't?