Heho, Ok, for those who are (potentially) interested, I just setup some more MTA-STS domains with slight deviations; Will debug the lib shared earlier a bit with those.
measurem...@mail-mtasts-n-iv.measurement.email-security-scans.org : MX has non-matching, expired certificate, policy delimited with \n measurem...@mail-mtasts-rn-iv.measurement.email-security-scans.org : MX has non-matching, expired certificate, policy delimited with \r\n measurem...@mail-mtasts-n-plain.measurement.email-security-scans.org : MX does not advertise starttls, policy delimited with \n measurem...@mail-mtasts-rn-plain.measurement.email-security-scans.org : MX does not advertise starttls, policy delimited with \r\n measurem...@mail-mtasts-n-mult-ivv.measurement.email-security-scans.org : Two MX; prio 10 has non-matching, expired certificate, prio 50 has valid TLS certificat, policy delimited with \n measurem...@mail-mtasts-rn-mult-ivv.measurement.email-security-scans.org : Two MX; prio 10 has non-matching, expired certificate, prio 50 has valid TLS certificat, policy delimited with \r\n measurem...@mail-mtasts-n-mult-ivp.measurement.email-security-scans.org : Two MX; prio 10 does not advertise starttls, prio 50 has non-matching, expired certificate, policy delimited with \n measurem...@mail-mtasts-rn-mult-ivp.measurement.email-security-scans.org : Two MX; prio 10 does not advertise starttls, prio 50 has non-matching, expired certificate, policy delimited with \r\n With best regards, Tobias -----Original Message----- From: mailop <[email protected]> On Behalf Of Tobias Fiebig via mailop Sent: Tuesday, 9 August 2022 19:46 To: 'Tobias Fiebig' <[email protected]>; 'Luis E. Muñoz' <[email protected]> Cc: [email protected]; 'Eric Tykwinski' <[email protected]> Subject: Re: [mailop] Debugging MTA-STS sending Heho, Debugging this further, "MTA-STS DNS Policy" is also marked x when the TXT record is present but the policy is faulty, e.g., due to a non-compliant MX. So, everything as it should be in this case. With best regards, Tobias -- Dr.-Ing. Tobias Fiebig T +31 616 80 98 99 M [email protected] -----Original Message----- From: mailop <[email protected]> On Behalf Of Tobias Fiebig via mailop Sent: Tuesday, 9 August 2022 17:57 To: 'Luis E. Muñoz' <[email protected]> Cc: [email protected]; 'Eric Tykwinski' <[email protected]> Subject: Re: [mailop] Debugging MTA-STS sending Heho, Currently not sue why the DNS policy is missing. Will revisit the RFC, might be due to ttl. dig +short TXT _mta-sts.mail-mtasts.measurement.email-security-scans.org "v=STSv1; id=2022080902" With best regards, Tobias -----Original Message----- From: Luis E. Muñoz <[email protected]> Sent: Tuesday, 9 August 2022 17:11 To: Tobias Fiebig <[email protected]> Cc: Eric Tykwinski <[email protected]>; [email protected] Subject: Re: [mailop] Debugging MTA-STS sending On 9 Aug 2022, at 10:27, Tobias Fiebig via mailop wrote: > This is interesting. The certificate for tls-invalid should a) not match the > CN, and b) be expired. The ": b'84:OK secure > match=tls-invalid.measurement.email-security-scans.org servername=hostname,'" > is hence a bit confusing. Also just tested it with 'openssl s\_client > -starttls smtp -crlf -connect > tls-invalid.measurement.email-security-scans.org:25' just now, and the CN > does indeed not match. https://esmtp.email/tools/mta-sts/ also is reporting on a missing DNS policy. The cert is reported as expired as well. -lem _______________________________________________ mailop mailing list [email protected] https://list.mailop.org/listinfo/mailop _______________________________________________ mailop mailing list [email protected] https://list.mailop.org/listinfo/mailop _______________________________________________ mailop mailing list [email protected] https://list.mailop.org/listinfo/mailop
