• Security

Outgoing Message Security Settings Now Available In The Control Panel

Josh Odom
5 min read

This was announced on December 2, 2015.

Before the birth of the modern Internet, e-mail was primarily used for exchanging messages across private networks where there was minimal risk of interception. As the use of e-mail proliferated for business and e-commerce purposes, mail delivery continued to rely on protocols that were not designed with information security concerns in mind. Over time, techniques were developed and adopted to improve the security of e-mail as it traveled across the Internet.

One of the techniques used to improve the security of email is to encrypt the SMTP communication channel through a technique known as TLS (transport layer security). TLS ensures that a message and its metadata is encrypted as it passes between the sending and receiving mail server. It’s important to note that the scope of TLS is simply to encrypt data in transit. It does not enforce any security guarantee regarding how the message is stored or delivered to the recipient.

Adoption of TLS in the Industry

With the rapid increase in adoption of TLS over the last several years, providers, including Gmail, are preparing to notify users when they receive messages that have not been encrypted in transit. Mailgun is prepared for this important change in the industry.

Mailgun Supports TLS

By default, Mailgun attempts to take advantage of TLS when it is supported by the receiving mail server. In these exchanges, we also check the validity and legitimacy of the mail server’s certificate. In situations where a server doesn’t support TLS, we simply send the message unencrypted. For many users, these are reasonable defaults, however, more companies have requirements that mandate the use of TLS for message exchange. As of today, Mailgun gives you the ability to configure these settings in the control panel on a per-domain basis.

Once you navigate to your domain, you can expand the “Security Settings for Outgoing Mail” section where you will be able to configure whether the domain forces TLS or uses the default opportunistic mode and if strict certificate validation is enforced.

Mailgun also offers the ability to configure these settings on a per-message basis. Any setting that is applied at the message level overrides the settings applied to the domain. More information about setting and configuring the TLS settings for your domain is available in our documentation.

If you have questions about this new feature, please reach out to a member of our support team by creating a ticket in the Help Center.


Learn about our Deliverability Services

Looking to send a high volume of emails? Our email experts can supercharge your email performance. See how we've helped companies like Lyft, Shopify, Github increase their email delivery rates to an average of 97%.

Learn More

Last updated on September 16, 2020

  • Related posts
  • Recent posts
  • Top posts
View all

Always be in the know and grab free email resources!

No spam, ever. Only musings and writings from the Mailgun team.

By sending this form, I agree that Mailgun may contact me and process my data in accordance with its Privacy Policy.

sign up
It's easy to get started. And it's free.
See what you can accomplish with the world's best email delivery platform.
Sign up for Free