
McAfee SaaS Email Protection Training Guide – Group Administrator Role
Proprietary and Confidential Page 7-8
7.5. Enforced TLS
7.5.1. What is TLS? (Transport Layer Security)
The Transport Layer Security (TLS) system allows client/server applications to communicate across
a network to prevent the possibility of message corruption or forgery. TLS provides confidentiality by
encrypting segments of network connections to provide security and data integrity.
This is accomplished by encrypting messages from mail server to mail server. This encryption
makes it more difficult for hackers to intercept and read messages.
7.5.2. What is Enforced TLS?
Enforced TLS is a new policy option that forces inbound or outbound mail to be delivered via TLS for
specified domains. Delivery is denied if TLS cannot be negotiated for a specified domain. The
ability to turn on and send a notification to both the sender and recipient of the message informing
them of the non-delivery is available.
Note: TLS requires a conversation between our mail transfer agent and the customers to be
successful. The customer must have TLS turned on to accommodate this transaction. Refer to your
MTA software manual on “How to enable/turn-on TLS” to ensure TLS is implemented in your system
prior to setting up your domain lists.
TLS Encryption is currently supported by the Email Protection Service. Without enabling
Enforced TLS Policy, the TLS Encryption will work as follows:
If a TLS connection can be negotiated between the sender and the recipient MTAs, then the
system delivers the email over TLS
If a TLS connection CANNOT be established between the sender or the recipient MTA, then
the mail transfer agent delivers, via SMTP, without encryption
7.5.3. Enabling Enforced TLS
Enabling Enforced TLS will ensure that the connection from the specified domains(s) in your
policy must be made via a TLS connection.
When TLS Policy is enabled, the TLS Encryption will work as follows:
If the sending or receiving Domains MTA cannot support TLS Encryption, the message will be
denied
A bounce message would be delivered to the sender / the recipient of the message notifying
them that the message was not delivered, if notifications are enabled
Enforced TLS can be enabled for both Inbound and Outbound Policies
Can enter up to 1,500 entries per policy
Entry must be a fully qualified Domain name (domain.com, domain.net)
Note: Every domain to which you want to enforce TLS must be listed in the Domain List; there is no
“enforce TLS for all messages” option.
When enabling Enforced TLS on any policy other than the Default, a ‘subscribe to Default TLS List’
checkbox is available. When checked, the TLS list on the Default policy of the same direction, in
addition to the entries on this policy TLS List, will be used when filtering mail for users associated to
this policy.
Comentarios a estos manuales