How does it differ from STARTTLS opportunistic encryption?
STARTTLS is opportunistic encryption. Servers attempt encryption but fall back to plaintext if encryption fails. This makes it vulnerable to STARTTLS stripping attacks where an active attacker removes the STARTTLS offer and forces clear text.
MTA STS removes that fallback. If encryption fails delivery must stop.
STARTTLS is a polite request. MTA STS is a firm requirement.
Was this answer helpful?
Thanks for your feedback!