* They provide a band aid, mostly, for SMTP port 25. For MTA-STS there is a PR pending. DNSSEC: we'll see. But still then we cannot label the server side as secure, as every client would need to test for that. Take this communication as an example: For SMTP and mail server to mail server communication it is still common to send e-mails to a mail server if the server certificate does not validate. Also if it validates properly we can tell whether all sending mail server does that. If we would label this as secure it would give you a false sense of security.
0 commit comments