Re: Validating MTA-STS setup, by writing to improperly configured MTA-STS sites
Daniel Margolis <[email protected]> Fri, 14 Jan 2022 09:51:53 +0100
| Newsgroups | gmane.ietf.smtp |
|---|---|
| Message-ID | <CANtKdUcswAeoe-j=nmi0CrRmV+C-GkLeEWtvj9goP4eC7WQ_EA@mail.gmail.com> |
Even easier, you could just set up a domain/subdomain (say, " test.yourdomain.com") with a valid MX but an MTA-STS policy that lists the wrong MX names. E.g. you could add: an MX record of aspmx.l.google.com a TXT record of _mta-sts = "v=STSv1; id=whatever;" and at https://mta-sts.[yourdomain]/.well-known/mta-sts.txt you would serve version: STSv1 mode: enforce *mx: comcast.net <http://comcast.net>* max_age: 86400 No need to mess about with the MTA at all if you just want to ensure that name mismatches are caught/enforced. :) I do think it would be worthwhile to have multiple subdomains with different failure modes for more complete testing, but if you just want to see if at least some validation is happening, the above is the easiest way to check, I think. Dan On Mon, Jan 10, 2022 at 8:52 PM Brotman, Alex <Alex_Brotman= [email protected]> wrote: > Could you simulate this by having your outbound not attempt STARTTLS > (perhaps just to a specific host)? If your MTA code understands the > difference between not-offered and not-attempted, that wouldn't work. Just > a thought. > > -- > Alex Brotman > Sr. Engineer, Anti-Abuse & Messaging Policy > Comcast > > > -----Original Message----- > > From: ietf-smtp <[email protected]> On Behalf Of ????? ???????? > > Sent: Monday, January 10, 2022 11:53 AM > > To: [email protected] > > Subject: [ietf-smtp] Validating MTA-STS setup, by writing to improperly > > configured MTA-STS sites > > > > Hello, > > > > I want to validate, that outgoing MTA-STS does work correctly. I want to > > send an email to a site, which has broken MTA-STS, and see what happens. > > > > Can somebody name a sample site, which (on purpose, for testing purposes, > > unintentionally for the moment) announces MTA-STS, but does not offer > > STARTTLS? > > > > I found only > > https://urldefense.com/v3/__https://mtasts.xyz/__;!!CQl3mcHX2A!TTR4o6 > > 1qatE9S6m9-9E3V266j07tny3GsF_Gb-Cme7r- > > bqM2EnnrsBWVuvBYC0D3pGbE_raAtg$ trying to perform outbound tests, > > but its MTA-STA setup is too broken - the certificates are outdated and > the > > HTTP-policy is thus ignored. > > > > Greetings > > Дилян > > > > _______________________________________________ > > ietf-smtp mailing list > > [email protected] > > https://urldefense.com/v3/__https://www.ietf.org/mailman/listinfo/ietf- > > smtp__;!!CQl3mcHX2A!TTR4o61qatE9S6m9-9E3V266j07tny3GsF_Gb-Cme7r- > > bqM2EnnrsBWVuvBYC0D3pGYo8Sdz-Q$ > _______________________________________________ > ietf-smtp mailing list > [email protected] > https://www.ietf.org/mailman/listinfo/ietf-smtp > -- How's my emailing? http://go/dan-email-slo _______________________________________________ ietf-smtp mailing list [email protected] https://www.ietf.org/mailman/listinfo/ietf-smtp