home.social

#tlsrpt — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #tlsrpt, aggregated by home.social.

fetched live
  1. TLS-RPT: the protocol your DMARC vendor probably doesn't support

    When a sending server can't establish a TLS connection to your mail server

    e.g. a certificate mismatch, expired cert, DANE validation failure, MTA-STS policy violation

    TLS-RPT sends you a report

    without it, encrypted delivery fails silently

    you'd never know that a major sender has been falling back to plaintext (or not delivering at all) for weeks

    dmarcguard.io/learn/tls-rpt/

    #DMARC #EmailSecurity #TLSRPT

  2. Eine weitere sehr gute Nachricht in dieser Woche ist, dass der deutsche E-Mail-Dienst Posteo, nachdem er 2016 schon erfolgreich nach Version 1 der BSI TR-03108 zertifiziert wurde, gestern vom @bsi die Zertifizierung für die Version 2 erhalten hat 💪😊 Das Zertifizierungsverfahren wird mit einer unabhängigen Prüfstelle anhand der zur TR gehörigen Prüfspezifikation durchgeführt und ist echt nicht ohne. Auch die Anforderungen sind mit der Version 2 nochmal deutlich gestiegen, z.B. muss TLS-Reporting ein- und ausgehend implementiert werden. Hut ab 🎩👌 :drake_like:

    posteo.de/blog/posteo-erh%C3%A

    #EMailSecurity #MailSecurity #DANE #DNSSEC #TLSRPT

  3. Die kürzlich veröffentlichte Cyber-Sicherheitsempfehlung "Upgrade für die E-Mail-Sicherheit" ist ein Paradebeispiel für die lösungsorientierte Zusammenarbeit zwischen verschiedenen Abteilungen im BSI. Nur so konnten wir praxisnahe Empfehlungen aussprechen, die auf Beobachtungen der echten Welt da draußen beruhen. Oft können Unternehmen, die E-Mails über eine eigene Domain senden und empfangen, nämlich schon mit überschaubaren Aufwand ihre Sicherheit deutlich verbessern.

    bsi.bund.de/DE/Service-Navi/Pr

    #MailSecurity #TeamBSI #SPF #DKIM #DMARC #STARTTLS #DNSSEC #DANE #MTASTS #TLSRPT

  4. My presentation on #TLSRPT, which I gave at #FOSDEM25 this weekend, is online: video.fosdem.org/2025/k4601/fo

    The audio is low volume because unfortunately my mic was muted for most of the time. Wearing a headphone worked for me when I watched ist.

  5. I enjoyed giving a presentation on #TLSRPT yesterday at #fosdem25 very much. It brings the best out of me when I stand in front of an audience, especially when I’m given the opportunity to speak about email security. If you want to know more about #TLSRPT check my slides: sys4.de/fosdem/tlsrpt.html.

  6. Going to FOSDEM? Join me at the „modern email“-track fosdem.org/2025/schedule/track and listen to my presentation on TLSRPT: fosdem.org/2025/schedule/event

    My company @sys4 developed a free low-level C-library and a tlsrpt-reporter so TLSRPT can come to Open Source. Together with Wietse Venema we’ve implemented it in Postfix. The upcoming version 3.10 will ship it: postfix.org/TLSRPT_README.html. Documentation to show you how to set the report service up and use it is on the way.#postfix #TLSRPT

  7. Claudia Plattner, President of German BSI, has just been featured in an article on email security in eco's dotmagazine. It's a wake up call and invitation to enhance email security in a joined effort :blobs:

    I like it :ablobsmile:

    dotmagazine.online/issues/digi

    #SPF #DKIM #DMARC #DANE #TLSA #MTASTS #TLSRPT #Mailsecurity #TeamBSI @bsi

  8. The Internet Security Days 2024 marked the starting point for a new effort by eco and @bsi to raise adoption of modern email security standards across Germany and worldwide. I'm honored that I was allowed to shape some of the contents of this great event and mailsecurity is finally getting the attention it deserves 💌 :blobcatthx:

    international.eco.de/news/inte

    #DMARC #SPF #DKIM #DANE #TLSA #MTASTS #TLSRPT #Mailsecurity #TeamBSI

  9. #MTA-STS is een light versie van #DANE, maar lastiger op te zetten. Heb je eenmaal #DNSSEC, dan kun je beter DANE toepassen.

    Interessant is dat je #TLSRPT ook in combinatie met DANE kunt gebruiken!

    #InternetSecurity #infosec

  10. did _not_ install MTA-STS today, as it's a mere quick-fix for mail domains that don't have DNSSEC yet. But I did install TLSRPT on my DNSSEC & DANE enabled domains. First (empty, cause everything is fine) reports from Google are coming in 👍

    #DNSSEC #DANE #TLSRPT #DNSsecurity #InternetSecurity

  11. I very much recommend this article on #EmailSecurity written by my colleague Kristina for eco's dotmagazine :blobcatreading: It'll give you a brief overview on both of our Technical Guidelines (BSI TR-03108 and BSI TR-03182) and what we released them for 😀👍

    dotmagazine.online/issues/buil

    #SPF #DKIM #DMARC #DANE #TLSA #MTASTS #TLSRPT #Mailsecurity #TeamBSI

  12. #Email can be confusing. There's the big three -- #SPF, #DKIM, and #DMARC -- but do you know how to test #MTASTS, #DANE, #TLSRPT, or #BIMI? And what about #DNSSEC?

    My colleagues have asked me the same questions, so my new#opensource #PowerShell module goes out to every sysadmin, #Office365 administrator, account manager, #mailsec worker, and help desk technician out there. MailPolicyExplainer will explain it all to you. github.com/rhymeswithmogul/Mai

  13. Hey @Vivaldi noticed that vivaldi.net is one of the all-greens on Hardenize.
    I'd move my mails to vivaldi.net, but I have size worries, still use other providers, & own domain.
    Do you have any plans to implement paid size plan, & features like automatic IMAP fetch, external sending SMTP, own domain management?

    #vivaldi #netsecurity #netsec #websecurity #websec #mailsecurity #mailsec #dnssec #dane #tls #tlsrpt #mtasts #spf #dmarc #dkim #security #privacy