technical · sourced answer
STARTTLS: Secure SMTP Communication via Opportunistic TLS
STARTTLS is an SMTP service extension that allows an insecure connection to be upgraded to a secure one using TLS. It enables a client and server to negotiate a secure channel over a single port, ensuring that email content and authentication credentials are encrypted during transit.
Mechanical Operation
The process begins with a standard plain text SMTP handshake. The server advertises STARTTLS capability in its EHLO response. The client then issues the STARTTLS command. If the server accepts, both parties perform a TLS handshake to establish encryption. Once the secure layer is active, the session continues with standard SMTP commands, but all subsequent data is encrypted.
Importance for Senders
STARTTLS prevents eavesdropping and man in the middle attacks by encrypting the communication path between mail servers. Without it, SMTP traffic travels in cleartext, exposing sensitive message bodies and login credentials to anyone monitoring the network path. Most modern receiving servers prioritize or require encrypted connections to accept mail.
Operational Considerations
A critical risk is the downgrade attack, where an attacker strips the STARTTLS command from the server response, forcing the client to send mail in plain text. To prevent this, administrators can implement MTA-STS or configure mandatory TLS. Using SendHQ free tools (https://sendhq.cc/tools) can help verify your general domain configuration for better delivery.
Common Implementation Mistakes
A frequent error is confusing STARTTLS with Implicit TLS. STARTTLS starts on a plain text port (like 587) and upgrades, whereas Implicit TLS (port 465) requires a secure handshake before any SMTP commands are sent. Misconfiguring the port or failing to provide a valid SSL certificate will cause connection failures or fallback to insecure transmission.
Concrete Example
A client connects to port 587 and sends EHLO. The server responds with 250-STARTTLS. The client sends STARTTLS. The server responds 220 Ready to start TLS. The client and server negotiate keys and encrypt the session. The client then sends AUTH LOGIN to securely provide credentials without exposing them to the network.
Questions teams ask
Is STARTTLS the same as SSL/TLS?
STARTTLS is a command used to initiate a TLS session on an existing plain text connection, while SSL/TLS refers to the underlying encryption protocols themselves.
What happens if STARTTLS fails?
By default, most servers use opportunistic TLS, meaning they fall back to plain text if the handshake fails, unless mandatory TLS is explicitly configured.
Which port is typically used for STARTTLS?
Port 587 is the standard submission port for STARTTLS, though it is also frequently used on port 25 for server to server relay.