Enforced TLS based on Sender via ESA
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-11-2023 07:58 AM
I have a requirement from a business unit to enforce TLS delivery for all outbound SMTP messages by a sending email address. Any message that cannot be delivered, they are wanting a custom delivery failure to occur. I know you can do it based off IP/domain via the sender group but the sending system has other SMTP traffic that originates from that IP address. Any assistance would be appreciated.
- Labels:
-
Email Security
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-11-2023 08:12 AM
Outbound mail config is per domain, and is done on Mail Policies/Destination Controls. You set the domain, and what limits you want, enforce TLS and what to happen when you it fails.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-11-2023 08:18 AM
Is there a way to make it required TLS based off the sending email address (example: secure@domain.com) while others from that same domain use preferred TLS (example: joeblow@domain.com) ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-11-2023 08:37 AM
By default we try to encrypt everything ("Default" set to 'Preferred'). We get ~95%
We've got 15 or so "Required" domains, I've gotten 2 bounces from that failing in 10 years.
