Umbra Wiki rfc rfc/RFC8460
Back to wiki

RFC8460 — SMTP TLS Reporting

provenance: imported · standards: RFC8460

RFC8460: SMTP TLS Reporting

IETF Request for Comments

Status PROPOSED STANDARD
Publication status PROPOSED STANDARD
Published September 2018
Stream IETF
Obsoletes
Obsoleted by
Updated by

Abstract

A number of protocols exist for establishing encrypted channels between SMTP Mail Transfer Agents (MTAs), including STARTTLS, DNS- Based Authentication of Named Entities (DANE) TLSA, and MTA Strict Transport Security (MTA-STS). These protocols can fail due to misconfiguration or active attack, leading to undelivered messages or delivery over unencrypted or unauthenticated channels. This document describes a reporting mechanism and format by which sending systems can share statistics and specific information about potential failures with recipient domains. Recipient domains can then use this information to both detect potential attacks and diagnose unintentional misconfigurations.

Official sources

  • Info page: https://www.rfc-editor.org/info/rfc8460
  • Full text: https://www.rfc-editor.org/rfc/rfc8460.txt
  • HTML: https://www.rfc-editor.org/rfc/rfc8460.html

Abstract and metadata are reproduced from the public RFC index; the full text is linked, not copied.