1
SMTP MTA STS available?
Question asked by Roger - 5/19/2023 at 5:43 AM
Unanswered
Hello together

I wanted to ask if in SmarterMail somewhere can enable SMTP MTA STS? according to my test it is currently not active see MTA-STS Validator (esmtp.email) or MTA-STS Lookup - Check domains for Inbound Transport Layer Security (TLS) Enforcement - MxToolbox 

6 Replies

Reply to Thread
0
Sorry Roger, what do you mean by "STS support" and what are the errors you see in https://ssl-tools.net/mailservers?

These are my results (note that tls 1.3 and DANE are not enabled because of me, I will enable them in the next days if I can...):



Gabriele Maoret - Head of SysAdmins at SERSIS Currently manages 6 SmarterMail installations (1 in the cloud for SERSIS which provides services to a few hundred third-party email domains + 5 on-premise for customers who prefer to have their mail server in-house)
0
Sabatino Replied
Hi Gabriel
Why do you keep SSLv3 enabled?
Sabatino Traini Chief Information Officer Genial s.r.l. Martinsicuro - Italy
0
Roger Replied
Mail Transfer Agent-Strict Transport Security (MTA-STS) is an email protocol that encrypts incoming email with a security layer. This enables TLS-encrypted communication between SMTP servers, which in turn prevents man-in-the-middle attacks.

The MTA-STS policy is designed to prevent attackers from tampering with the content of emails or sending the communication to a different address. Unlike STARTTLS, MTA Strict Transport Security keeps TLS always on. It tells sending servers that your e-mail server accepts delivery of e-mail only over a secure connection.
1
Ciao Sabatino!

Ho avvisato i clienti che sarà disabilitato con il 01/06/2023 (ho ancora qualche cliente che ha dei software vecchi che non supportano TLS, ma ora gli ho dato l'ultimatum...)
Gabriele Maoret - Head of SysAdmins at SERSIS Currently manages 6 SmarterMail installations (1 in the cloud for SERSIS which provides services to a few hundred third-party email domains + 5 on-premise for customers who prefer to have their mail server in-house)
0
Roger Replied
I found out how to implement it. It is basically independent from SmarterMail see this tutorial. It works for me now

0
Patrick Jeski Replied
Just to update this, even though .well-known is the the IIS tree as an actual directory under the SmarterMail site, I think ARR is not letting it work and I don't know how to deal with it. Also my BIMI image, which I placed in MRS, no longer works. I'm just not good enough with IIS honestly.

In any case, dropping a file in .well-known on Build 8684 works as I would expect. I submitted a ticket.

Earlier:
Roger, I’m having trouble figuring out where to put the policy file. There is a .well-known folder in my MRS folder, so I put it there and the MTA checker I’m using can’t retrieve the file.


Reply to Thread