In reply to STARTTLS Considered Harmful

Reader Mike Spooner on 2017-08-27 at 11:23:

Re "dedicated TLS ports are still widely supported by ... client email implementations".

On the desktop and perhaps tablets too, that assertion is mostly accurate, but on mobile ('droid phones, iOS) it really isn't, even as late as 2017... most such apps give encryption config choices of "TLS", "TLS (dont check certificate)" or "None" - however, this almost always actually means "STARTTLS" or "None", and not straight TLS.



