Re: Validating MTA-STS setup, by writing to improperly configured MTA-STS sites

Daniel Margolis <[email protected]> Fri, 14 Jan 2022 09:51:53 +0100
Newsgroups gmane.ietf.smtp
Message-ID <CANtKdUcswAeoe-j=nmi0CrRmV+C-GkLeEWtvj9goP4eC7WQ_EA@mail.gmail.com>
Even easier, you could just set up a domain/subdomain (say, "
test.yourdomain.com") with a valid MX but an MTA-STS policy that lists the
wrong MX names.

E.g. you could add:

an MX record of aspmx.l.google.com
a TXT record of _mta-sts = "v=STSv1; id=whatever;"

and at https://mta-sts.[yourdomain]/.well-known/mta-sts.txt you would serve

version: STSv1
mode: enforce
*mx: comcast.net <http://comcast.net>*
max_age: 86400

No need to mess about with the MTA at all if you just want to ensure that
name mismatches are caught/enforced. :)

I do think it would be worthwhile to have multiple subdomains with
different failure modes for more complete testing, but if you just want to
see if at least some validation is happening, the above is the easiest way
to check, I think.


Dan

On Mon, Jan 10, 2022 at 8:52 PM Brotman, Alex <Alex_Brotman=
[email protected]> wrote:

> Could you simulate this by having your outbound not attempt STARTTLS
> (perhaps just to a specific host)? If your MTA code understands the
> difference between not-offered and not-attempted, that wouldn't work.  Just
> a thought.
>
> --
> Alex Brotman
> Sr. Engineer, Anti-Abuse & Messaging Policy
> Comcast
>
> > -----Original Message-----
> > From: ietf-smtp <[email protected]> On Behalf Of ????? ????????
> > Sent: Monday, January 10, 2022 11:53 AM
> > To: [email protected]
> > Subject: [ietf-smtp] Validating MTA-STS setup, by writing to improperly
> > configured MTA-STS sites
> >
> > Hello,
> >
> > I want to validate, that outgoing MTA-STS does work correctly.  I want to
> > send an email to a site, which has broken MTA-STS, and see what happens.
> >
> > Can somebody name a sample site, which (on purpose, for testing purposes,
> > unintentionally for the moment) announces MTA-STS, but does not offer
> > STARTTLS?
> >
> > I found only
> > https://urldefense.com/v3/__https://mtasts.xyz/__;!!CQl3mcHX2A!TTR4o6
> > 1qatE9S6m9-9E3V266j07tny3GsF_Gb-Cme7r-
> > bqM2EnnrsBWVuvBYC0D3pGbE_raAtg$  trying to perform outbound tests,
> > but its MTA-STA setup is too broken - the certificates are outdated and
> the
> > HTTP-policy is thus ignored.
> >
> > Greetings
> >   Дилян
> >
> > _______________________________________________
> > ietf-smtp mailing list
> > [email protected]
> > https://urldefense.com/v3/__https://www.ietf.org/mailman/listinfo/ietf-
> > smtp__;!!CQl3mcHX2A!TTR4o61qatE9S6m9-9E3V266j07tny3GsF_Gb-Cme7r-
> > bqM2EnnrsBWVuvBYC0D3pGYo8Sdz-Q$
> _______________________________________________
> ietf-smtp mailing list
> [email protected]
> https://www.ietf.org/mailman/listinfo/ietf-smtp
>


-- 
How's my emailing? http://go/dan-email-slo

_______________________________________________
ietf-smtp mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ietf-smtp