Skip to content

Archive

Email Security

4 articles
Cybersecurity 24 Sep 2026 7 min read

MTA-STS Pins SMTP Delivery to TLS-Capable Hosts

SMTP was designed to move mail between independently operated systems, and opportunistic STARTTLS was added later. That upgrade improves confidentiality when both sides support it, but opportunistic behavior has a structural weakness: if TLS negotiation fails, a sender may still deliver over plaintext. An active network attacker that can interfere with SMTP traffic can exploit that fallback by suppressing STARTTLS or redirecting delivery toward an unintended host. MTA-STS, standardized in RFC 8461, gives a receiving domain a way to state a stricter policy. A supporting sender retrieves that policy over HTTPS, caches it, and applies it to future SMTP delivery. In enforcement mode, the sender requires both an authorized MX host and a valid TLS connection before transmitting the message.

Cybersecurity 24 Sep 2026 6 min read

MTA-STS Pins SMTP Delivery to Authenticated TLS

SMTP commonly upgrades a plaintext connection with STARTTLS. Without an authenticated transport policy, that upgrade can remain opportunistic: a sender may continue delivery when TLS is unavailable, depending on its configuration. An active intermediary that can interfere with the SMTP exchange can exploit that flexibility by suppressing the STARTTLS capability or redirecting delivery. MTA Strict Transport Security (MTA-STS), defined by RFC 8461, gives a recipient domain a policy that compliant sending MTAs can cache and enforce. The policy states which MX hosts are acceptable and whether delivery requires TLS with a certificate that passes PKIX validation.

Cybersecurity 23 Sep 2026 5 min read

MTA-STS Enforces Authenticated TLS for SMTP Delivery

MTA-STS Enforces Authenticated TLS for SMTP Delivery SMTP STARTTLS can encrypt mail transport, but ordinary opportunistic TLS permits delivery to continue when encryption is unavailable. That compatibility behavior leaves room for an active intermediary to suppress STARTTLS or redirect delivery toward an unintended server. SMTP MTA Strict Transport Security, defined by RFC 8461, gives a recipient domain a policy channel for conforming sending MTAs. The policy states which MX hosts are acceptable and whether delivery must use TLS with a valid PKIX certificate. In enforce mode, a sender does not silently downgrade when those checks fail.

Cybersecurity 23 Sep 2026 5 min read

DMARC Ties Mail Authentication to the Visible From Domain

Email can carry several domain identities at once. The address displayed in the From header can differ from the envelope sender used by SMTP, while a DKIM signature can name yet another domain in its d= tag. SPF and DKIM authenticate identities from those separate protocol layers; neither mechanism alone requires its authenticated domain to match the domain presented to a recipient in From. Domain-based Message Authentication, Reporting, and Conformance (DMARC), specified in RFC 7489, connects those layers. A receiver evaluates SPF and DKIM, tests domain alignment against the RFC5322.From domain, and obtains a policy published by that domain. A message passes DMARC when at least one qualifying SPF or DKIM path both authenticates successfully and aligns.