Guidance on End-to-End Email Security
RFC 9787, “Guidance on End-to-End Email Security”, is an Informational document published in August 2025 by D. K. Gillmor, A. Melnikov, B. Hoeneisen. The canonical text is published by the RFC Editor.
Abstract
End-to-end cryptographic protections for email messages can provide useful security. However, the standards for providing cryptographic protection are extremely flexible. That flexibility can trap users and cause surprising failures. This document offers guidance for Mail User Agent (MUA) implementers to help mitigate those risks and to make end-to-end email simple and secure for the end user. It provides a useful set of vocabulary as well as recommendations to avoid common failures. It also identifies a number of currently unsolved usability and interoperability problems.
What “Informational” means
Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.
The canonical text of RFC 9787 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9786 EVPN Port-Active Redundancy Mode
- RFC 9788 Header Protection for Cryptographically Protected Email
- RFC 9785 Preference-Based EVPN Designated Forwarder Election
- RFC 9789 MPLS Network Actions Framework
- RFC 9784 Virtual Ethernet Segments for EVPN and Provider Backbone Bridge EVPN
- RFC 9790 IANA Registry and Processing Recommendations for the First Nibble Following a Label Stack
- RFC 9783 Arm's Platform Security Architecture Attestation Token
- RFC 9791 Use Cases for MPLS Network Action Indicators and Ancillary Data