1. MTA-STS

RFC8461 SMTP MTA Strict Transport Security (MTA-STS)

https://datatracker.ietf.org/doc/html/rfc8461

https://maildata.jp/specification/mta-sts.html

1.1. MTA-STSのプロセス

3.1. MTA-STS TXT Records

_mta-sts.gmail.com.     300     IN      TXT     "v=STSv1; id=20190429T010101;"

3.2. MTA-STS Policies

The Policy Host DNS name is constructed by prepending "mta-sts" to the Policy Domain.

ポリシーファイルは、RFC5785の規定に沿って、「.well-known」というフォルダに「mta-sts.txt」というファイル名で保存します。

https://mta-sts.gmail.com/.well-known/mta-sts.txt

version: STSv1
mode: enforce
mx: gmail-smtp-in.l.google.com
mx: *.gmail-smtp-in.l.google.com
max_age: 86400

1.2. 接続手順

5.1. Policy Application Control Flow

  1. For each candidate MX, in order of MX priority, attempt to deliver the message.
    • If a policy is present with an "enforce" mode,
      • when attempting to deliver to each candidate MX, ensure STARTTLS support and host identity validity as described in Section 4, "Policy Validation".
      If a candidate fails validation, continue to the next candidate (if there is one).


CategoryDns CategoryWatch CategoryTemplate

MoinQ: RFC/8461 (last edited 2023-12-11 12:02:21 by ToshinoriMaeno)