Understanding the Encryption, StartTLS vs SSL/TLS or nothing

As title.

Is it good to use StartTLS over the SSL/TLS?

What is the advantages and what the disadvantages?

Suppose that I use no encryption at all when sending email on port 25. What is the possible security issue that I can experience?

Thanks.

4 Replies

is there someone on this forum? :)

where did you go?

Probably because basic FYI type questions are better researched on the web, then asking on a community support site (i.e. Google it).

Now if you had a specific question on how to setup SMTP security, that would probably get more attention.

As to do you need to encrypt SMTP traffic, only you know if the traffic is worth securing (well you, and the CIA if you're here in the States).

AFAIK, the only advantage of using STARTTLS is that you can accept both plain-text connections and encrypted connections on the same port (25 for SMTP). So you can have your MTA listen on only one port, instead of two or more ports.

I'm not sure if this is a real advantage, because it's not like you're going to run anything else on ports 465 and 587 anyway, and also because some clients have difficulty connecting to port 25 due to ISP firewalls.

@vonskippy:

Probably because basic FYI type questions are better researched on the web, then asking on a community support site (i.e. Google it).

Now if you had a specific question on how to setup SMTP security, that would probably get more attention.

As to do you need to encrypt SMTP traffic, only you know if the traffic is worth securing (well you, and the CIA if you're here in the States).

try answering with a link and yes I have a question.

http://forum.linode.com/viewtopic.php?t=8010

Reply

Please enter an answer
Tips:

You can mention users to notify them: @username

You can use Markdown to format your question. For more examples see the Markdown Cheatsheet.

> I’m a blockquote.

I’m a blockquote.

[I'm a link] (https://www.google.com)

I'm a link

**I am bold** I am bold

*I am italicized* I am italicized

Community Code of Conduct