STARTTLS considered harmful
STARTTLS considered harmful
Posted Aug 18, 2021 4:27 UTC (Wed) by derobert (subscriber, #89569)In reply to: STARTTLS considered harmful by wtarreau
Parent article: STARTTLS considered harmful
I run my own mailserver and use Let's Encrypt, wwhich works fine. Both administration-wise and performance-wise, enabling TLS is insignificant. Spam filtering, deliverability, etc. are the hard things; TLS is trivial.
Honestly, I already have a list of domains configured in that (a) require TLS and (b) verify the cert. E.g., if I send something to a Gmail address, it will verify that and (eventually) bounce if it can't securely send. It doesn't take many domains to cover a good portion of outgoing email (especially on my small mailserver).