Transport Layer Security (TLS) is a protocol that helps to secure
data and ensure communication privacy between endpoints. Cloud Email Gateway
Protection allows you to configure TLS encryption
policies between Cloud Email Gateway
Protection and specified TLS
peers. Cloud Email Gateway
Protection supports the following TLS
protocols in descending order of priority: TLS 1.3, TLS 1.2, TLS 1.1 and TLS
1.0.
To prevent against man-in-the-middle attacks on TLS connections, Cloud Email Gateway
Protection introduces DNS-based Authentication of
Named Entities (DANE) and Mail Transfer Agent - Strict Transport Security (MTA-STS)
to
verify the identity of the destination servers.
NoteYou can enable DANE or MTA-STS authentication between Cloud Email Gateway
Protection and specified TLS peers during
outbound mail delivery.
For inbound mails, Cloud Email Gateway
Protection inherently supports
MTA-STS after you have set up a DNS record and a policy for your domain. For
details, see About mta-sts records for inbound protection.
|
The Transport Layer Security (TLS) Peers
screen uses the following important terms:
Term
|
Details
|
||
Managed Domain list
|
|||
Status (Managed Domain)
|
|
||
Default (for unspecified domains)
|
This configuration applies to all domains that are not in the
managed domain list
|
||
Domain TLS Peers list
|
|||
Status (TLS Peer)
|
|
||
TLS peer
|
Cloud Email Gateway
Protection can apply your
specified TLS configuration with this peer during network communications.
|
||
Minimum TLS version
|
Minimum TLS version that the TLS peer must use to communicate with
Cloud Email Gateway
Protection through the TLS
protocol.
|
||
Security level
|
|
||
Default (for unspecified peers)
|
This configuration applies to all peers that meet any of the
following criteria:
|