RFC 8461 Proposed Standard

SMTP MTA Strict Transport Security (MTA-STS)

D. Margolis, M. Risher, B. Ramakrishnan, A. Brotman, J. Jones · 2018-09

Abstract

SMTP MTA Strict Transport Security (MTA-STS) is a mechanism enabling mail service providers to declare their ability to receive Transport Layer Security (TLS) secure SMTP connections and to specify whether sending SMTP servers should refuse to deliver to MX hosts that do not offer TLS with a trusted server certificate.

Why This RFC Matters

RFC 8461 addressed the longstanding weakness in SMTP's opportunistic TLS model, where an attacker performing a downgrade or MITM attack could strip TLS from email delivery without detection. MTA-STS allows domain owners to publish a policy (via a well-known HTTPS URL) declaring that all inbound SMTP connections must use TLS with a valid certificate, and sending MTAs that honor MTA-STS will refuse to deliver in plaintext. Combined with SMTP TLS Reporting (RFC 8460), MTA-STS gives email administrators visibility into delivery failures and active downgrade attempts, significantly strengthening the email security posture for domains that deploy it.

관련 프로토콜

관련 용어

Security에서 더 보기