A Multifaceted Study on the Use of TLS and Auto-detect in Email Ecosystems
Ka Fun Tang, Che Wei Tu, Sui Ling Angela Mak, Sze Yiu Chau
Abstract
—Various email protocols, including IMAP, POP3, and SMTP, were originally designed as “plaintext” protocols without inbuilt confidentiality and integrity guarantees. To protect the communication traffic, TLS can either be used implicitly before the start of those email protocols, or introduced as an opportunistic upgrade in a post-hoc fashion. In order to improve user experience, many email clients nowadays provide a so-called “auto-detect” feature to automatically determine a functional set of configuration parameters for the users. In this paper, we present a multifaceted study on the security of the use of TLS and auto-detect in email clients. First, to evaluate the design and implementation of client-side TLS and auto-detect, we tested 49 email clients and uncovered various flaws that can lead to covert security downgrade and exposure of user credentials to attackers. Second, to understand whether current deployment practices adequately avoid the security traps introduced by opportunistic TLS and auto-detect, we collected and analyzed 1102 email setup guides from academic institutes across the world, and observed problems that can drive users to adopt insecure email settings. Finally, with the server addresses obtained from the setup guides, we evaluate the sever-side support for implicit and opportunistic TLS, as well as the characteristics of their certificates. Our results suggest that many users suffer from an inadvertent loss of security due to careless handling of TLS and auto-detect, and organizations in general are better off prescribing concrete and detailed manual configuration to their users.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 268da5be-bab9-4d0a-bfed-2305ae7e847aBuilds on11
- TLS in the Wild: An Internet-wide Analysis of TLS-based Protocols for Electronic CommunicationRalph Holz, Johanna Amann, Olivier Mehani, Mohamed Ali Kâafar et al.NDSS 2016 · 117 citations
- Killed by Proxy: Analyzing Client-end TLS Interception SoftwareXavier de Carné de Carnavalet, Mohammad MannanNDSS 2016 · 90 citations
- Why TLS is better without STARTTLS: A Security Analysis of STARTTLS in the Email ContextDamian Poddebniak, Fabian Ising, Hanno Böck, Sebastian SchinzelUSENIX Security 2021 · 25 citations
- All your Credentials are Belong to Us: On Insecure WPA2-Enterprise ConfigurationsMan Hong Hue, Joyanta Debnath, Kin Man Leung, Li Li et al.CCS 2021 · 14 citations
- Assessing certificate validation user interfaces of WPA supplicantsKailong Wang, Yuwei Zheng, Qing Zhang, Guangdong Bai et al.MobiCom 2022 · 10 citations
Related papers
- Automatic Insecurity: Exploring Email Auto-configuration in the WildShushang Wen, Yiming Zhang, Yuxiang Shen, Bingyu Li et al.NDSS 2025
- Opossum Attack: Application Layer Desynchronization using Opportunistic TLSRobert Merget, Nurullah Erinola, Marcel Maehren, Lukas Knittel et al.USENIX Security 2026
- Not that Simple: Email Delivery in the 21st CenturyFlorian Holzbauer, Johanna Ullrich, Martina Lindorfer, Tobias FiebigUSENIX ATC 2022 · 18 citations
- Extended Hell(o): A Comprehensive Large-Scale Study on Email Confidentiality and Integrity Mechanisms in the WildBirk Blechschmidt, Ben StockUSENIX Security 2023
- "I Have No Idea What I'm Doing" - On the Usability of Deploying HTTPSKatharina Krombholz, Wilfried Mayer, Martin Schmiedecker, Edgar R. WeipplUSENIX Security 2017 · 114 citations
