Skip to main content
HOME/
RFC 8461 / TLS-RPT
Initializing MTA-STS & STARTTLS Inspector Engine...
// ARCHITECTURAL SPECIFICATION

Email Transport Encryption & STRIPTLS Downgrade Defense

Why Opportunistic STARTTLS Fails

SMTP STARTTLS was designed as an in-band protocol upgrade (RFC 3207). If an attacker intercepts the initial plaintext connection, they can remove the 250-STARTTLS capability advertisement from the server response. Sending servers silently fall back to transmitting emails in unencrypted plain text.

How MTA-STS Enforces Cryptographic Privacy

By publishing a DNS signal at _mta-sts and hosting an HTTPS policy file, domain owners force sending MTAs (including Gmail, Outlook 365, and Yahoo) to cache the policy. Any connection without authenticated TLS is rejected, rendering MITM wiretapping impossible.