mail: require TLS to the relay !491

merged merged by cmc on 2026-09-28 21:50 UTC · krz/gitbay:mail-require-tls into main

Discussion

cmc

Outbound mail requires TLS to a non-local relay.

  • mail.require_tls (unset means on for every relay except localhost and loopback addresses): if the relay does not offer STARTTLS, or the handshake fails, delivery fails instead of sending in clear. require_tls = false restores the old behaviour.
  • mail.tls = "implicit" dials TLS directly (port 465 when none is given). Both modes verify the relay's certificate against its host name.
  • Tests use a local fake relay with a generated certificate.
  • Admin and Architecture pages; #280 leaves Known-Gaps; CHANGELOG.

bay1's relay (AWS mail manager, port 587) negotiates STARTTLS (TLS 1.3, checked 2026-09-28), so the new default does not stop its mail.

Stacked on !490.

Closes #280