Skip to Content [alt-c]

Comment

In reply to Comment by Reader Charles

Andrew Ayer on 2014-08-13 at 14:41:

If by "SMTP client" you mean a mail user agent (MUA) like Thunderbird, Mail.app, Outlook, etc., then I think the popular ones probably do it correctly. I'd be concerned about less popular ones that have received less scrutiny.

If by "SMTP client" you mean a mail transfer agent (MTA) that's sending mail server-to-server, then they intentionally allow downgrades, because not all MTAs accept mail over TLS. Since this is intentional and currently unavoidable, I'm not really talking about this case. I'm more concerned with the client to server scenario which is virtually always expected to be secure.

Reply

Post a Reply

Your comment will be public. If you would like to contact me privately, please email me. Please keep your comment on-topic, polite, and comprehensible.

(Optional; will be published)

(Optional; will not be published)

(Optional; will be published)

  • Blank lines separate paragraphs.
  • Lines starting with ">" are indented as block quotes.
  • Lines starting with two spaces are reproduced verbatim.
  • Text surrounded by *asterisks* is italicized.
  • Text surrounded by `back ticks` is monospaced.
  • URLs are turned into links.
  • Use the Preview button to check your formatting.