Outbound mail uses STARTTLS only when the relay advertises it (internal/mail/mail.go). A network attacker can strip the advertisement and read verification codes and login links in transit. Go's PlainAuth still refuses to send the SMTP password over plaintext to a non-local host, so credentials are safe; message bodies are not.
mail.require_tls = true(default on for non-local relays), failing delivery instead of sending in clear.- Implicit TLS on port 465 as an option.
referenced in commit 4e0958a163 by cmc: plans: open issues from the architecture and UX reviews
2026-09-28 05:43 UTC