SMTP Require TLS Option
RFC 8689, “SMTP Require TLS Option”, is a Proposed Standard document published in November 2019 by J. Fenton. The canonical text is published by the RFC Editor.
Abstract
The SMTP STARTTLS option, used in negotiating transport-level encryption of SMTP connections, is not as useful from a security standpoint as it might be because of its opportunistic nature; message delivery is, by default, prioritized over security. This document describes an SMTP service extension, REQUIRETLS, and a message header field, TLS-Required. If the REQUIRETLS option or TLS-Required message header field is used when sending a message, it asserts a request on the part of the message sender to override the default negotiation of TLS, either by requiring that TLS be negotiated when the message is relayed or by requesting that recipient-side policy mechanisms such as MTA-STS and DNS-Based Authentication of Named Entities (DANE) be ignored when relaying a message for which security is unimportant.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 8689 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 8688 A Session Initiation Protocol Response Code for Rejected Calls
- RFC 8690 Clarification of Segment ID Sub-TLV Length for RFC 8287
- RFC 8687 OSPF Routing with Cross-Address Family Traffic Engineering Tunnels
- RFC 8691 Basic Support for IPv6 Networks Operating Outside the Context of a Basic Service Set over IEEE Std 802.11
- RFC 8692 Internet X.509 Public Key Infrastructure: Additional Algorithm Identifiers for RSASSA-PSS and ECDSA Using SHAKEs
- RFC 8685 Path Computation Element Communication Protocol Extensions for the Hierarchical Path Computation Element Architecture
- RFC 8694 Applicability of the Path Computation Element to Inter-area and Inter-AS MPLS and GMPLS Traffic Engineering
- RFC 8683 Additional Deployment Guidelines for NAT64/464XLAT in Operator and Enterprise Networks