Both prevent SMTP STARTTLS downgrade. DANE requires DNSSEC on the zone and publishes cert pins in TLSA records. MTA-STS uses HTTPS + a DNS TXT record — no DNSSEC required, easier to deploy. Trade-offs: DANE has stronger cryptographic anchoring (DNSSEC chain of trust); MTA-STS has lower operational cost. Some SMTP receivers implement both; Postfix + Exim support both; Google Workspace supports MTA-STS but not DANE for inbound.
All questions