tutao / tutanota

Tuta is an email service with a strong focus on security and privacy that lets you encrypt emails, contacts and calendar entries on all your devices.
https://tuta.com
GNU General Public License v3.0
6.11k stars 526 forks source link

Support MTA-STS (MTA Strict Transport Security) #461

Closed armhub closed 4 years ago

armhub commented 6 years ago

Check support here: https://www.hardenize.com/report/tutanota.com/1531686822#email_mta_sts Some information here: https://www.hardenize.com/blog/mta-sts

armhub commented 6 years ago

Check how it can be supported for custom domains.

ofiqfakj commented 5 years ago

Please enable MTA-STS. Its still not enabled.

charlag commented 5 years ago

@ofiqfakj please stop. Your nagging won't make us faster (quite the contrary reading it will slow us down).

ofiqfakj commented 5 years ago

Thanks for the fast reply. I dont think its a slowdown when i show interest in a security optimization option that is not enabled now. Its just showing the opposite of what 99% of the people of the planet show - no knowledge in encryption and its relevance for privacy.

ghost commented 4 years ago

Seriously @charlag? That's how you reply to your user base on a public forum? I always knew Germans were cold, but that was stone cold and rude. Also, MTA-STS is a quick, easy win that doesn't require any code changes.

ci70 commented 4 years ago

Status update please?

bedhub commented 4 years ago

fixed server side

ralexander-phi commented 1 month ago

It looks like MTA-STS is supported for in-bound messages. Is MTA-STS supported for out-bound messages as well? As in, will Tuta check MTA-STS for recipient domains and perform TLS validation as needed? This appears to be missing.