Re: QUIC vs. SMTP

Paul Vixie <paul@redbarn.org> Fri, 27 February 2026 08:21 UTC

Return-Path: <paul@redbarn.org>
X-Original-To: quic@mail2.ietf.org
Delivered-To: quic@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id B4D27BF6237C for <quic@mail2.ietf.org>; Fri, 27 Feb 2026 00:21:42 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (1024-bit key) header.d=redbarn.org
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id erakbgLfythL for <quic@mail2.ietf.org>; Fri, 27 Feb 2026 00:21:41 -0800 (PST)
Received: from util.redbarn.org (util.redbarn.org [IPv6:2001:559:8000:cd::222]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id C2924BF62375 for <quic@ietf.org>; Fri, 27 Feb 2026 00:21:41 -0800 (PST)
Received: from family.redbarn.org (family.redbarn.org [IPv6:2001:559:8000:cd::5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "*.redbarn.org", Issuer "Sectigo Public Server Authentication CA DV R36" (not verified)) by util.redbarn.org (Postfix) with UTF8SMTPS id D4FBC160B99; Fri, 27 Feb 2026 08:21:39 +0000 (UTC)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=redbarn.org; s=util; t=1772180499; bh=w3WYCmVrsYlgidUqVUH8JhyHohzjbBFK7IYr9hopiXU=; h=Date:From:To:Cc:In-Reply-To:References:Subject; b=RxrEzMBPzuQUVwhmK26R24DcdFBVlTX1b3wGAHLvrygvIFpVzA76LNeSnZ/ygw7L5 HgEaIPdezKh7hFjxm8IjUIOtlctwpsfbaZLpPl12MfqiHDyhHwcJwHaeYX+zw1dVLS 6uCs52mD9t1ym/smaRaapcrVq2WbClwqoX6mOQR4=
Received: from dummy.faircode.eu (clnet-p10-045.ikbnet.co.at [83.175.84.45]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by family.redbarn.org (Postfix) with UTF8SMTPSA id DA51F19; Fri, 27 Feb 2026 08:21:39 +0000 (UTC)
Date: Fri, 27 Feb 2026 09:21:33 +0100
From: Paul Vixie <paul@redbarn.org>
To: John R Levine <johnl@taugh.com>
Message-ID: <c5d4aa77-4838-4f82-9153-c7aa1e2b7faf@redbarn.org>
In-Reply-To: <1a397635-267c-8f8e-4f97-9567968a3969@taugh.com>
References: <b2ad8b20-3dd0-10c6-745d-a54fc3856fb1@taugh.com> <E092359D-89BA-4CCC-B2CC-9D7708AC6CC2@gmail.com> <40428219-da8c-3a39-b70b-9ae6334c82f6@taugh.com> <7052e4ad-a8a5-42f4-85ad-2a7ea73072ef@redbarn.org> <1a397635-267c-8f8e-4f97-9567968a3969@taugh.com>
Subject: Re: QUIC vs. SMTP
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="----=_Part_1_258100450.1772180493537"
X-Correlation-ID: <c5d4aa77-4838-4f82-9153-c7aa1e2b7faf@redbarn.org>
Message-ID-Hash: LYGGKD5QLNQEDGGP5R3MQ5NGT7HMARI3
X-Message-ID-Hash: LYGGKD5QLNQEDGGP5R3MQ5NGT7HMARI3
X-MailFrom: paul@redbarn.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-quic.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Dan Wing <danwing@gmail.com>, quic@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
List-Id: Main mailing list of the IETF QUIC working group <quic.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/quic/4FlDFBCrB3djtO2QEdkum9sr-Cs>
List-Archive: <https://mailarchive.ietf.org/arch/browse/quic>
List-Help: <mailto:quic-request@ietf.org?subject=help>
List-Owner: <mailto:quic-owner@ietf.org>
List-Post: <mailto:quic@ietf.org>
List-Subscribe: <mailto:quic-join@ietf.org>
List-Unsubscribe: <mailto:quic-leave@ietf.org>

"Port 465 is used for SMTPS, which is the secure version of the Simple Mail Transfer Protocol (SMTP). It employs implicit TLS encryption to secure email transmissions between clients and servers, ensuring that messages cannot be easily intercepted or tampered with."

I realize that ietf believes otherwise but the market has spoken.
Paul Vixie

Feb 26, 2026 18:25:42 John R Levine <johnl@taugh.com>:

>> Starttls, in both SMTP and IMAP, can be mitm'd (injection of refusal). We should not be using them any more.
> 
> Not for SMTP if you use MTA-STS or DANE TLSA.
> 
> In any event, in SMTP the only alternative to STARTTLS is not to use STARTTLS, which I don't think anyone would say was an improvement.
> 
> R's,
> John
> 
>> Paul Vixie
>> 
>> Feb 26, 2026 17:57:47 John R Levine <johnl@taugh.com>:
>> 
>>> On Wed, 25 Feb 2026, Dan Wing wrote:
>>>> One approach would be take idea of https://datatracker.ietf.org/doc/html/rfc8314 and extend it include SMTP itself, which would bring QUIC along doing a happy eyeballs-like attempt at QUIC falling back to TLS-over-TCP falling back to TCP-port-25-STARTTLS falling back to TCP-port-25 plaintext, or as Martin suggested have DNS optimize those choices.
>>> 
>>> The problem with that is that SMTP doesn't do the TLS handshake at startup, only after a STARTTLS command in the TCP session.  But see next message.