Re: QUIC vs. SMTP
John Levine <johnl@taugh.com> Fri, 27 February 2026 14:49 UTC
Return-Path: <johnl@taugh.com>
X-Original-To: quic@mail2.ietf.org
Delivered-To: quic@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 7ABD3BFA8878 for <quic@mail2.ietf.org>; Fri, 27 Feb 2026 06:49:29 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -4.4
X-Spam-Level:
X-Spam-Status: No, score=-4.4 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=iecc.com header.b="elxJWoZu"; dkim=pass (2048-bit key) header.d=taugh.com header.b="iLUgwhOH"
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id q3oA1Otn7y_J for <quic@mail2.ietf.org>; Fri, 27 Feb 2026 06:49:28 -0800 (PST)
Received: from gal.iecc.com (gal.iecc.com [IPv6:2001:470:1f07:1126:0:43:6f73:7461]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 4E5A0BFA862D for <quic@ietf.org>; Fri, 27 Feb 2026 06:49:15 -0800 (PST)
Received: (qmail 4334 invoked from network); 27 Feb 2026 14:49:08 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed; d=iecc.com; h=date:message-id:from:to:cc:content-type:content-transfer-encoding:mime-version:subject:references:in-reply-to; s=10eb69a1aee4.k2602; t=1772203738; x=1772549338; i=johnl-iecc.com@submit.iecc.com; bh=92BA4HyDAnnBafWlZmgIIDvijqJMiN104aWP2mmGUzY=; b=elxJWoZu68kuU81BQge3YBmjA4uFVTRkndpS7wx60cKCqFKjytOlWJYQ8tfFA985B8FLRbrj5wbQRiy5a9PlFyqQJqattuacEeWdrOdoi8msdig9TZv1GmvA5cvSTFR20jjBKFWwWT7azqSv3rNfLMN3J5wRf3nvhUAEWfHRPXB5KIRpCOadVgJ8eI+rAp+84pmPEM/FaMqsWRv4tHh5R419UsdSrAxfk+REi20uFP1yFmrVr/9zWKyw6Og2A0fns1FRxDpo3bvSBOgMcLz0VYAateywD4l7vF8riAae8i6IfoP1NmVcjjGqwxBirwsalntojKQGBmph4gXOI/g6uw==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed; d=taugh.com; h=date:message-id:from:to:cc:content-type:content-transfer-encoding:mime-version:subject:references:in-reply-to; s=10eb69a1aee4.k2602; olt=johnl-iecc.com@submit.iecc.com; bh=92BA4HyDAnnBafWlZmgIIDvijqJMiN104aWP2mmGUzY=; b=iLUgwhOHEpk7dqdD7NjKsgSB+ogiVZuBDwyuAYMAhO8v5mhBM1uKRSegccO0sHM6iktgclK++F0mqy/Y/y9LyJ1poKxeSrhxgByGUCryDFtl4es0m8wdV2FRlY/KWmlQrOTpyi2EIWF7Cmq2zR7+65WBkIUh1ftssM/i29fqATd2MpkDyHU3inPrrKEEWZHzitaMdcJUVOZS9AMHrz0iFAdCVRCVXgg9d5nOmkMgHXqXruThv+TiyHxQ+M3udgjxoRArY2cwgWzMzJKutL06UmghM2KIKAKG1BAs/8z4eemPUfa7O9sQSXGKV+dzqboBbsorg0mtKfvR9Ik1GOM8RA==
Received: from smtpclient.apple ([64.246.233.201]) by imap.iecc.com ([192.55.226.69]) with ESMTPSA (TLS1.3 ECDHE-RSA AES-256-GCM AEAD, johnl@iecc.com) via TCP; 27 Feb 2026 14:49:08 -0000
Date: Fri, 27 Feb 2026 09:48:56 -0500
Message-Id: <05E98D88-8684-49FC-82C0-9AC6917B5528@taugh.com>
From: John Levine <johnl@taugh.com>
To: Paul Vixie <paul@redbarn.org>
Content-Type: multipart/alternative; boundary="Apple-Mail-4EF9DD05-967F-4AA5-8305-61003D73779F"
Content-Transfer-Encoding: 7bit
Mime-Version: 1.0 (1.0)
Subject: Re: QUIC vs. SMTP
References: <c5d4aa77-4838-4f82-9153-c7aa1e2b7faf@redbarn.org>
In-Reply-To: <c5d4aa77-4838-4f82-9153-c7aa1e2b7faf@redbarn.org>
X-Mailer: iPad Mail (23D127)
Message-ID-Hash: TCD4QII4ZLQGLN7V5A7DEB75OU3RPHOH
X-Message-ID-Hash: TCD4QII4ZLQGLN7V5A7DEB75OU3RPHOH
X-MailFrom: johnl@taugh.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-quic.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Dan Wing <danwing@gmail.com>, quic@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
List-Id: Main mailing list of the IETF QUIC working group <quic.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/quic/bPdCFgx33Z-SRqNGBvrbf_Kt3uY>
List-Archive: <https://mailarchive.ietf.org/arch/browse/quic>
List-Help: <mailto:quic-request@ietf.org?subject=help>
List-Owner: <mailto:quic-owner@ietf.org>
List-Post: <mailto:quic@ietf.org>
List-Subscribe: <mailto:quic-join@ietf.org>
List-Unsubscribe: <mailto:quic-leave@ietf.org>
That is submission, not SMTP. It works great from your mail program to your mail server, not between one mail server and another. That’s why SMTP needs MTA-STS or TLSA. Having written the STARTTLS code for the mail server I use, and temporarily made it impossible for my wife to get mail from her mother due to broken TLSA, I’m not guessing here. Please consider the environment before reading this message. John Levine, johnl@taugh.com > On Feb 27, 2026, at 03:21, Paul Vixie <paul@redbarn.org> wrote: > > "Port 465 is used for SMTPS, which is the secure version of the Simple Mail Transfer Protocol (SMTP). It employs implicit TLS encryption to secure email transmissions between clients and servers, ensuring that messages cannot be easily intercepted or tampered with." > > I realize that ietf believes otherwise but the market has spoken. > Paul Vixie > Feb 26, 2026 18:25:42 John R Levine <johnl@taugh.com>: > > Starttls, in both SMTP and IMAP, can be mitm'd (injection of refusal). We should not be using them any more. > > Not for SMTP if you use MTA-STS or DANE TLSA. > > In any event, in SMTP the only alternative to STARTTLS is not to use STARTTLS, which I don't think anyone would say was an improvement. > > R's, > John > > Paul Vixie > > Feb 26, 2026 17:57:47 John R Levine <johnl@taugh.com>: > > On Wed, 25 Feb 2026, Dan Wing wrote: > One approach would be take idea of https://datatracker.ietf.org/doc/html/rfc8314 and extend it include SMTP itself, which would bring QUIC along doing a happy eyeballs-like attempt at QUIC falling back to TLS-over-TCP falling back to TCP-port-25-STARTTLS falling back to TCP-port-25 plaintext, or as Martin suggested have DNS optimize those choices. > > The problem with that is that SMTP doesn't do the TLS handshake at startup, only after a STARTTLS command in the TCP session. But see next message.
- QUIC vs. SMTP John R Levine
- Re: QUIC vs. SMTP John R Levine
- Re: QUIC vs. SMTP Martin Thomson
- Re: QUIC vs. SMTP Dan Wing
- Re: QUIC vs. SMTP John R Levine
- Re: QUIC vs. SMTP Paul Vixie
- Re: QUIC vs. SMTP John R Levine
- Re: QUIC vs. SMTP Francesco Chemolli
- Re: QUIC vs. SMTP Paul Vixie
- Re: QUIC vs. SMTP John R Levine
- Re: QUIC vs. SMTP Francesco Chemolli
- Re: QUIC vs. SMTP John Levine
- Re: QUIC vs. SMTP John Levine