Re: [mailop] Gmail deferrals resolved by transit encryption

2023-11-17 Thread Jeroen via mailop
Hi, Two things can be true at the same time. The OP did not say that you will never have deferrals once you turn on STARTTLS. He said that he had deferrals without STARTTLS that went away with STARTTLS. It is definitely possible that STARTTLS influences behaviours and limits, just as IPv4 vs

Re: [mailop] Gmail deferrals resolved by transit encryption

2023-11-17 Thread Jeroen via mailop
We use an MTA which supports STARTTLS, sending the message data through an encrypted channel for servers which support it (like Google). Thank you for enabling opportunistic STARTTLS - you've stepped up the game for both yourself and possible clients. However, it is not something that will

Re: [mailop] Success MiTM attack

2023-10-22 Thread Jeroen via mailop
I read that they were able to redirect the traffic to their own machine, and therefore perform an http-01 challenge like anyone else. Which can effectively be mitigated by using DNSSEC, DANE and CAA. Browser support for DANE is currently rather poor, but most MTAs and MUAs support it out of