1
SMTP MTA STS available?
Question asked by Roger S. - 5/19/2023 at 5:43 AM
Unanswered
Hello together

I wanted to ask if in SmarterMail somewhere can enable SMTP MTA STS? according to my test it is currently not active see MTA-STS Validator (esmtp.email) or MTA-STS Lookup - Check domains for Inbound Transport Layer Security (TLS) Enforcement - MxToolbox 

5 Replies

Reply to Thread
0
Sorry Roger, what do you mean by "STS support" and what are the errors you see in https://ssl-tools.net/mailservers?

These are my results (note that tls 1.3 and DANE are not enabled because of me, I will enable them in the next days if I can...):



Gabriele Maoret - Head of SysAdmins at SERSIS
Currently manages 3 SmarterMail installations (1 in cloud for SERSIS which provides service to a few hundreds 3rd party Mail Domains + 2 on premise to customers)
0
Sabatino Replied
Hi Gabriel
Why do you keep SSLv3 enabled?
Sabatino Traini
      Chief Information Officer
Genial s.r.l. 
Martinsicuro - Italy

0
Roger S. Replied
Mail Transfer Agent-Strict Transport Security (MTA-STS) is an email protocol that encrypts incoming email with a security layer. This enables TLS-encrypted communication between SMTP servers, which in turn prevents man-in-the-middle attacks.

The MTA-STS policy is designed to prevent attackers from tampering with the content of emails or sending the communication to a different address. Unlike STARTTLS, MTA Strict Transport Security keeps TLS always on. It tells sending servers that your e-mail server accepts delivery of e-mail only over a secure connection.
1
Ciao Sabatino!

Ho avvisato i clienti che sarà disabilitato con il 01/06/2023 (ho ancora qualche cliente che ha dei software vecchi che non supportano TLS, ma ora gli ho dato l'ultimatum...)
Gabriele Maoret - Head of SysAdmins at SERSIS
Currently manages 3 SmarterMail installations (1 in cloud for SERSIS which provides service to a few hundreds 3rd party Mail Domains + 2 on premise to customers)
0
Roger S. Replied
I found out how to implement it. It is basically independent from SmarterMail see this tutorial. It works for me now

Reply to Thread