RFC Knowledge Base

Comprehensive collection of Messaging Security RFCs with search and categorization

28 RFCs found

RFC 8689: SMTP Require TLS Option (REQUIRETLS)

Defines the REQUIRETLS SMTP extension that allows senders to require TLS for the entire message delivery path, preventing downgrade attacks.

SMTP TLS REQUIRETLS Email Security Encryption MTA
Published: 2019-11
TLS
RFC 8617: Authenticated Received Chain (ARC) Protocol

Defines ARC, a protocol that allows an intermediate mail handler to preserve email authentication results.

ARC Email Security Authentication Email
Published: 2019-07
ARC
RFC 8624: Algorithm Implementation Requirements and Usage Guidance for DNSSEC

Specifies which DNSSEC algorithms must, should, or must not be implemented by DNS software, including RSASHA256, ECDSAP256SHA256, and ED25519.

DNSSEC DNS Algorithms Security ECDSA ED25519
Published: 2019-06
DNSSEC
RFC 8551: Secure/Multipurpose Internet Mail Extensions (S/MIME) Version 4.0 Message Specification

Defines S/MIME version 4.0, providing encryption and digital signing capabilities for email messages.

S/MIME Encryption Email Security CMS Digital Signature
Published: 2019-04
S/MIME
RFC 8550: The Authenticated Received Chain (ARC) Protocol

Earlier version of ARC protocol specification.

ARC Email Security Authentication Email
Published: 2019-04
ARC
RFC 8553: DNS Attrleaf Changes: Fixing Specifications That Use Underscored Node Names

Documents conventions for underscore-prefixed DNS names used by various protocols including DMARC (_dmarc), DKIM (_domainkey), MTA-STS (_mta-sts), and TLSRPT (_smtp._tls).

DNS Underscore DMARC DKIM MTA-STS TLSRPT Conventions
Published: 2019-03
Email Security
RFC 8460: SMTP TLS Reporting (TLSRPT)

Defines a reporting mechanism for domains to publish policies on how sending MTAs can report on TLS connectivity failures. The report is published via a DNS TXT record at _smtp._tls.{domain}.

TLSRPT SMTP TLS DNS Reporting Email Security MTA
Published: 2018-09
TLS
RFC 8461: SMTP MTA Strict Transport Security (MTA-STS)

Defines MTA-STS, a mechanism enabling mail service providers to declare their ability to receive TLS-secured connections and to specify whether sending MTAs should refuse to deliver to MX hosts that do not offer TLS with a trusted certificate. Published as _mta-sts.{domain} TXT record.

MTA-STS SMTP TLS DNS Email Security MTA Transport Security
Published: 2018-09
TLS
RFC 8314: Cleartext Considered Obsolete: Use of Transport Layer Security (TLS) for Email Submission and Access

Deprecates the use of cleartext protocols for email submission and access, recommending TLS instead.

TLS Email Security SMTP IMAP POP3 Encryption
Published: 2018-01
TLS
RFC 7672: SMTP Security via Opportunistic DNS-Based Authentication of Named Entities (DANE) Transport Layer Security (TLS)

Defines how to use DANE with SMTP to authenticate mail servers and prevent man-in-the-middle attacks.

SMTP TLS DANE DNS Email Security Authentication
Published: 2016-06
TLS
RFC 7671: The DNS-Based Authentication of Named Entities (DANE) Protocol: Updates and Operational Guidance

Provides updates and operational guidance for DANE, including best practices for TLSA record management and interaction with certificate authorities.

DANE TLSA TLS DNS DNSSEC Operations
Published: 2015-10
TLS
RFC 7489: Domain-based Message Authentication, Reporting, and Conformance (DMARC)

Defines DMARC, a mechanism for email authentication that builds on SPF and DKIM to provide domain-level authentication and reporting.

DMARC Email Security Authentication DNS Email SPF DKIM
Published: 2015-03
DMARC
RFC 7208: Sender Policy Framework (SPF) for Authorizing Use of Domains in Email, Version 1

Defines the SPF protocol for email authentication, allowing domain owners to specify which mail servers are authorized to send email on their behalf.

SPF Email Security Authentication DNS Email
Published: 2014-04
SPF
RFC 6781: DNSSEC Operational Practices, Version 2

Provides guidance on DNSSEC operational practices including key management, key rollover procedures, and algorithm selection.

DNSSEC DNS Operations Key Rollover Security
Published: 2012-12
DNSSEC
RFC 6698: The DNS-Based Authentication of Named Entities (DANE) Transport Layer Security (TLS) Protocol: TLSA

Defines the TLSA DNS record type for storing TLS certificate information in DNS, enabling domain owners to specify which TLS certificates should be used for their services.

DANE TLSA TLS DNS DNSSEC Certificate Authentication
Published: 2012-08
TLS
RFC 6376: DomainKeys Identified Mail (DKIM) Signatures

Defines DKIM, a method for associating a domain name with an email message, allowing verification of the message's origin.

DKIM Email Security Authentication DNS Email Cryptographic
Published: 2011-09
DKIM
RFC 5750: STARTTLS and DANE in SMTP

Describes how to use STARTTLS with DANE (DNS-Based Authentication of Named Entities) for SMTP security.

SMTP TLS STARTTLS DANE DNS Email Security
Published: 2010-01
TLS
RFC 5598: Internet Mail Architecture

Provides an overview of the Internet mail architecture, including components, protocols, and security considerations.

Email Architecture SMTP MTA MUA Email Security
Published: 2009-07
Email Security
RFC 5321: Simple Mail Transfer Protocol

Defines the SMTP protocol for sending and receiving email messages over the Internet.

SMTP Email MTA Protocol
Published: 2008-10
SMTP
RFC 5322: Internet Message Format

Defines the format of Internet messages, including headers, body, and MIME structure.

Email Message Format MIME Headers
Published: 2008-10
Email Security
RFC 5280: Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile

Defines the profile for X.509 certificates used in Internet applications, including email security.

Certificate X.509 PKI TLS S/MIME Email Security
Published: 2008-05
Authentication
RFC 5155: DNS Security (DNSSEC) Hashed Authenticated Denial of Existence (NSEC3)

Defines NSEC3, an alternative to NSEC for authenticated denial of existence in DNSSEC that prevents zone enumeration by hashing domain names.

DNSSEC DNS NSEC3 Security Zone Enumeration
Published: 2008-03
DNSSEC
RFC 5084: Using AES-128-GCM and AES-256-GCM Authenticated Encryption in the Cryptographic Message Syntax (CMS)

Specifies the use of AES-GCM authenticated encryption algorithms in CMS for S/MIME, providing better security than traditional encryption methods.

S/MIME Encryption CMS Email Security AES GCM AEAD
Published: 2007-11
S/MIME
RFC 4033: DNS Security Introduction and Requirements (DNSSEC)

Introduces DNSSEC and specifies requirements for DNS data origin authentication and data integrity verification using public key cryptography.

DNSSEC DNS Security Authentication Cryptographic
Published: 2005-03
DNSSEC
RFC 4034: Resource Records for the DNS Security Extensions (DNSSEC)

Defines DNS resource record types for DNSSEC: DNSKEY, RRSIG, NSEC, and DS records used for DNS data authentication.

DNSSEC DNS DNSKEY RRSIG DS NSEC Security
Published: 2005-03
DNSSEC
RFC 4035: Protocol Modifications for the DNS Security Extensions (DNSSEC)

Specifies protocol changes for DNS resolvers and servers to support DNSSEC, including chain-of-trust validation from root to leaf zone.

DNSSEC DNS Validation Chain of Trust Security
Published: 2005-03
DNSSEC
RFC 3207: SMTP Service Extension for Secure SMTP over Transport Layer Security

Defines STARTTLS extension for SMTP, allowing clients to upgrade a plaintext connection to TLS.

SMTP TLS STARTTLS Encryption Email Security
Published: 2002-02
TLS
RFC 2986: PKCS #10: Certification Request Syntax Specification Version 1.7

Defines the syntax for certification requests used in certificate signing requests (CSR).

CSR Certificate PKCS TLS Encryption
Published: 2000-11
Authentication

No RFCs found

Try adjusting your search or filter criteria