#tlsrpt

2025-05-27

Die kürzlich veröffentlichte Cyber-Sicherheitsempfehlung "Upgrade für die E-Mail-Sicherheit" ist ein Paradebeispiel für die lösungsorientierte Zusammenarbeit zwischen verschiedenen Abteilungen im BSI. Nur so konnten wir praxisnahe Empfehlungen aussprechen, die auf Beobachtungen der echten Welt da draußen beruhen. Oft können Unternehmen, die E-Mails über eine eigene Domain senden und empfangen, nämlich schon mit überschaubaren Aufwand ihre Sicherheit deutlich verbessern.

bsi.bund.de/DE/Service-Navi/Pr

#MailSecurity #TeamBSI #SPF #DKIM #DMARC #STARTTLS #DNSSEC #DANE #MTASTS #TLSRPT

2025-02-27

Think you have your email hosted with @protonprivacy's Proton Mail set up right?
Your DMARC, SPF, DKIM, and TLS-RPT are all in order because DNS is easy, but what about MTA-STS?

See @wonderfall's "Setting up MTA-STS with a custom domain on Proton Mail"

wonderfall.dev/mta-sts/

#MTASTS #DMARC #SPF #DKIM #TLSRPT #DNS #ProtonMail #Email

Patrick Ben Koetter 🕺🏼patrickbenkoetter@troet.cafe
2025-02-04

My presentation on #TLSRPT, which I gave at #FOSDEM25 this weekend, is online: video.fosdem.org/2025/k4601/fo

The audio is low volume because unfortunately my mic was muted for most of the time. Wearing a headphone worked for me when I watched ist.

Patrick Ben Koetter 🕺🏼patrickbenkoetter@troet.cafe
2025-02-02

I enjoyed giving a presentation on #TLSRPT yesterday at #fosdem25 very much. It brings the best out of me when I stand in front of an audience, especially when I’m given the opportunity to speak about email security. If you want to know more about #TLSRPT check my slides: sys4.de/fosdem/tlsrpt.html.

Patrick Ben Koetter 🕺🏼patrickbenkoetter@troet.cafe
2025-01-28

Going to FOSDEM? Join me at the „modern email“-track fosdem.org/2025/schedule/track and listen to my presentation on TLSRPT: fosdem.org/2025/schedule/event

My company @sys4 developed a free low-level C-library and a tlsrpt-reporter so TLSRPT can come to Open Source. Together with Wietse Venema we’ve implemented it in Postfix. The upcoming version 3.10 will ship it: postfix.org/TLSRPT_README.html. Documentation to show you how to set the report service up and use it is on the way.#postfix #TLSRPT

2024-10-30

Claudia Plattner, President of German BSI, has just been featured in an article on email security in eco's dotmagazine. It's a wake up call and invitation to enhance email security in a joined effort :blobs:

I like it :ablobsmile:

dotmagazine.online/issues/digi

#SPF #DKIM #DMARC #DANE #TLSA #MTASTS #TLSRPT #Mailsecurity #TeamBSI @bsi

2024-09-25

The Internet Security Days 2024 marked the starting point for a new effort by eco and @bsi to raise adoption of modern email security standards across Germany and worldwide. I'm honored that I was allowed to shape some of the contents of this great event and mailsecurity is finally getting the attention it deserves 💌 :blobcatthx:

international.eco.de/news/inte

#DMARC #SPF #DKIM #DANE #TLSA #MTASTS #TLSRPT #Mailsecurity #TeamBSI

2024-08-20

#MTA-STS is een light versie van #DANE, maar lastiger op te zetten. Heb je eenmaal #DNSSEC, dan kun je beter DANE toepassen.

Interessant is dat je #TLSRPT ook in combinatie met DANE kunt gebruiken!

#InternetSecurity #infosec

2024-07-28

did _not_ install MTA-STS today, as it's a mere quick-fix for mail domains that don't have DNSSEC yet. But I did install TLSRPT on my DNSSEC & DANE enabled domains. First (empty, cause everything is fine) reports from Google are coming in 👍

#DNSSEC #DANE #TLSRPT #DNSsecurity #InternetSecurity

2024-06-25

I very much recommend this article on #EmailSecurity written by my colleague Kristina for eco's dotmagazine :blobcatreading: It'll give you a brief overview on both of our Technical Guidelines (BSI TR-03108 and BSI TR-03182) and what we released them for 😀👍

dotmagazine.online/issues/buil

#SPF #DKIM #DMARC #DANE #TLSA #MTASTS #TLSRPT #Mailsecurity #TeamBSI

Colin Cogle 🔵colincogle
2023-10-15

can be confusing. There's the big three -- , , and -- but do you know how to test , , , or ? And what about ?

My colleagues have asked me the same questions, so my new#opensource module goes out to every sysadmin, administrator, account manager, worker, and help desk technician out there. MailPolicyExplainer will explain it all to you. github.com/rhymeswithmogul/Mai

@zsoltsandor@social.lolzsoltsandor
2023-06-28

Hey @Vivaldi noticed that vivaldi.net is one of the all-greens on Hardenize.
I'd move my mails to vivaldi.net, but I have size worries, still use other providers, & own domain.
Do you have any plans to implement paid size plan, & features like automatic IMAP fetch, external sending SMTP, own domain management?

2022-12-27

Every SMTP TLS Reporting (RFC 8460) tutorial anywhere suggests adding #TLSRPT DNS records to *receive* TLS reports. From whom? If no-one (except for Google) is sending them, how would everyone magically receive any? We need a solution & tutorials for sending SMTP TLS reports, too! Do you know any?

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst