TLS Strategies¶
In the console: Settings › MTA › Outbound › TLS Strategies
When outgoing delivery must be encrypted, and how strictly certificates are checked. For specialists.
TLS Strategy¶
Name¶
Short identifier for the TLS strategy.
Text. Set when it’s created; can’t be changed afterwards. Name in the API: name.
Description¶
A short description of the TLS strategy, which can be used to identify it in the list of strategies.
Text. Name in the API: description.
Security Requirements¶
DANE¶
Whether DANE is required, optional, or disabled.
One of: Optional (optional), Required (require), Disabled (disable). Default: Optional. Name in the API: dane.
MTA-STS¶
Whether MTA-STS is required, optional, or disabled.
One of: Optional (optional), Required (require), Disabled (disable). Default: Optional. Name in the API: mtaSts.
STARTTLS¶
Whether TLS support is required, optional, or disabled.
One of: Optional (optional), Required (require), Disabled (disable). Default: Optional. Name in the API: startTls.
Allow Invalid Certs¶
Whether to allow connections to servers with invalid TLS certificates.
On or off. Name in the API: allowInvalidCerts.
Timeouts¶
TLS¶
Maximum time to wait for the TLS handshake to complete.
A length of time. Default: 3m. Name in the API: tlsTimeout.
MTA-STS¶
Maximum time to wait for the MTA-STS policy lookup to complete.
A length of time. Default: 5m. Name in the API: mtaStsTimeout.