4 ms·
This looks a lot like SPF. I've been looking if this has been implemented in Postfix and I found a past HN thread on it -- https://news.ycombinator.com/item?id
by prolepunk 7y ago
This looks a lot like SPF.
I've been looking if this has been implemented in Postfix and I found a past HN thread on it -- https://news.ycombinator.com/item?id=18091690 https://news.ycombinator.com/item?id=18091690
There's this project that provides mta-sts implementation -- https://github.com/ldelouw/postfix-mta-sts-resolver https://github.com/ldelouw/postfix-mta-sts-resolver
Has anyone used it and what is your experience?
- LeonM 7y agoMTA-STS is nothing like SPF. SPF is a method to publish a policy on which senders are allowed to use your domain so send email. MTA-STS is a method to force MTA's to only use and accept TLS encrypted connections when handling email send from your domain. The MTA-STS resolver you linked to is used to implement MTA-STS capability in Postfix MTA. It's intended for MTA administrators. You don't use the resolver to setup MTA-STS for your own send email, for that you must setup a DNS record and a HTTPS enabled webserver.
- megous 7y ago> MTA-STS is a method to force MTA's to only use and accept TLS It's still advisory information, like SPF. The other end has to implement it.
- LeonM 7y agoThat is correct. SPF, DKIM, DMARC, MTA-STS and TLS-RPT are all opt-in features for the receivers. One could say that email is the ultimate legacy product of the internet.