Skip to content

TLS Strategies

In the console: Settings › MTA › Outbound › TLS Strategies

When outgoing delivery must be encrypted, and how strictly certificates are checked. For specialists.

TLS Strategy

Name

Short identifier for the TLS strategy.

Text. Set when it’s created; can’t be changed afterwards. Name in the API: name.

Description

A short description of the TLS strategy, which can be used to identify it in the list of strategies.

Text. Name in the API: description.

Security Requirements

DANE

Whether DANE is required, optional, or disabled.

One of: Optional (optional), Required (require), Disabled (disable). Default: Optional. Name in the API: dane.

MTA-STS

Whether MTA-STS is required, optional, or disabled.

One of: Optional (optional), Required (require), Disabled (disable). Default: Optional. Name in the API: mtaSts.

STARTTLS

Whether TLS support is required, optional, or disabled.

One of: Optional (optional), Required (require), Disabled (disable). Default: Optional. Name in the API: startTls.

Allow Invalid Certs

Whether to allow connections to servers with invalid TLS certificates.

On or off. Name in the API: allowInvalidCerts.

Timeouts

TLS

Maximum time to wait for the TLS handshake to complete.

A length of time. Default: 3m. Name in the API: tlsTimeout.

MTA-STS

Maximum time to wait for the MTA-STS policy lookup to complete.

A length of time. Default: 5m. Name in the API: mtaStsTimeout.