Privacy controls
CyberFurl can load analytics only after you opt in. Core product features work without analytics consent.
Comprehensive evaluation of SMTP transport security, validating MTA-STS, DANE, and STARTTLS configurations against RFC 8461, RFC 6698, and RFC 3207 for defense against active downgrade and Man-in-the-Middle (MitM) attacks.
Mail transport security encompasses the cryptographic protocols and enforcement mechanisms—specifically Opportunistic TLS, MTA-STS, and DANE—designed to protect SMTP communications in transit. By default, SMTP transmits data in plaintext, exposing sensitive email contents to interception. Transport security ensures that MTAs encrypt the data channel using TLS before exchanging messages.
Opportunistic TLS (RFC 3207) leaves email transport vulnerable to STRIPTLS attacks, where active adversaries strip the STARTTLS command and force plaintext fallback. Without enforced transport security mechanisms like MTA-STS (Mail Transfer Agent Strict Transport Security) or DANE (DNS-based Authentication of Named Entities), MTAs cannot cryptographically verify the destination server's identity or enforce encrypted delivery, compromising confidentiality and integrity of email data in transit.
Failure to implement MTA-STS or DANE, relying solely on Opportunistic TLS.
DNS Interrogation: The tool fetches MX records and checks for the presence of DNSSEC, _mta-sts TXT records, and TLSA records on port 25.
MTA-STS Policy Validation: We attempt to retrieve the MTA-STS policy via HTTPS from mta-sts.[domain] and validate its syntax, max_age, and mx host constraints against RFC 8461.
DANE Authentication: For domains with DNSSEC and TLSA records, we cryptographically verify the certificate hash and usage types (e.g., 3 1 1) per RFC 6698.
STARTTLS Handshake Simulation: A connection is established to the MX hosts to verify TLS capabilities, cipher suites, and certificate validity chains.
Deep inspection of _mta-sts TXT records and HTTPS policy endpoints, checking for syntax validity, caching directives, and matching MX hosts.
Validates DNSSEC chains of trust and verifies TLSA records against the actual X.509 certificates presented by the SMTP server.
Analyzes the STARTTLS implementation for supported TLS versions (TLS 1.2/1.3), cipher suite strength, and certificate validity.
Ensures the domain's DNS zones are signed with DNSSEC, a prerequisite for DANE to prevent DNS spoofing attacks.
Evaluates the domain's susceptibility to STRIPTLS and active Man-in-the-Middle attacks based on current transport enforcement mechanisms.
Provides actionable remediation guidance mapped directly to RFC 8461, RFC 6698, and RFC 3207 standards.
Identify vulnerabilities in your STARTTLS, MTA-STS, and DANE configurations. Protect your domain against active downgrade attacks today.