TLS Protocols

Secure Mail Server Connection
Why this matters

TLS Protocols with weak security strength utilise old versions of TLS Cipher Suites that increase the surface for attackers to be able to perform eavesdropping.

Steps to fix
  1. Ask your System Administrator or mail provider which TLS Protocol versions your email servers currently support.
  2. Enable TLS 1.3 (preferred) and TLS 1.2 (sufficient) on every mail server, as recommended by NIST Special Publication 800-52 Revision 2.
  3. Turn off TLS 1.1, TLS 1.0, and any SSL versions — these are considered weak and should be disabled.
  4. Re-run the scan (Rescan domain) to confirm only strong TLS Protocol versions remain enabled.
View full technical scan details