TLS Cipher Suites
Secure Mail Server Connection
Why this matters
Bad TLS Cipher Suites are vulnerable to attacks. It provides an opportunity for attackers to intercept the data in transit between you and your recipients or vice versa. Attackers can then use the data for malicious activities.
Steps to fix
- Ask your System Administrator or hosting provider for the list of TLS Cipher Suites currently enabled on your mail servers.
- Cross-check that list against NIST Special Publication 800-52 Revision 2 and the Mozilla Wiki Security/Server Side TLS guidance for approved, strong cipher suites.
- Disable any cipher suites flagged as weak, including outdated Ephemeral Cipher curves called out in NIST Special Publication 800-56A Revision 3.
- Re-run the scan (Rescan domain) to confirm only strong cipher suites remain enabled.