USENIX Security2023Top-tier venue
Extended Hell(o): A Comprehensive Large-Scale Study on Email Confidentiality and Integrity Mechanisms in the Wild
Birk Blechschmidt, Ben Stock
Abstract
The core specifications of electronic mail as used today date back as early as the 1970s. At that time, security did not play a significant role in developing communication protocols. These shortcomings still manifest themselves today in the prevalence of phishing and the reliance on opportunistic encryption. Besides STARTTLS, various mechanisms such as SPF, DKIM, DMARC, DANE, and MTA-STS have been proposed. However, related work has shown that not all providers support them and that misconfigurations are common. In this work, we provide a comprehensive overview of the current state of email confidentiality and integrity measures, as well as the effectiveness of their deployment. On a positive note, support for incoming TLS connections has significantly increased over the years, with over 96% of reachable MXs in the top 10 million domains allowing for explicit TLS. Notably, 30% of presented certificates are invalid, though, with the majority of issues related to the presented hostnames. In light of this, all 47 providers we tested connect to hosts with expired, self-signed, non-matching certificates, making it trivial for attackers to intercept their connections. Our analysis also shows that still only around 40% of sites specify SPF, and even highranked providers like t-online.de do not enforce it. Similarly, while DNS lookups are performed for both DKIM and DANE, neither mechanism is validated or enforced by all providers. In addition, we show that MTA-STS is only slowly getting traction (six providers support it) and provide the first largescale analysis into OPENPGPKEY and SMIMEA records. All in all, this still paints a grim yet slightly improving picture for the state of email security by late 2022.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext da6e312e-9d8c-4648-a202-adc6ee9edf56Cited by top-tier papers6
- SPF Beyond the Standard: Management and Operational Challenges in Practice and Practical RecommendationsMd. Ishtiaq Ashiq, Weitong Li, Tobias Fiebig, Taejoong ChungUSENIX Security 2024 · 3 citations
- S/MINE: Collecting and Analyzing S/MIME Certificates at ScaleGurur Öndarö, Jonas Kaspereit, Samson Umezulike, Christoph Saatjohann et al.USENIX Security 2025
- A Multifaceted Study on the Use of TLS and Auto-detect in Email EcosystemsKa Fun Tang, Che Wei Tu, Sui Ling Angela Mak, Sze Yiu ChauNDSS 2025
- Email Spoofing with SMTP Smuggling: How the Shared Email Infrastructures Magnify this VulnerabilityChuhan Wang, Chenkai Wang, Songyi Yang, Sophia Liu et al.USENIX Security 2025
- A Large-Scale Measurement Study of the PROXY Protocol and its Security ImplicationsStijn Pletinckx, Christopher Kruegel, Giovanni VignaNDSS 2025
Builds on7
- You've Got Vulnerability: Exploring Effective Vulnerability NotificationsFrank Li, Zakir Durumeric, Jakub Czyz, Mohammad Karami et al.USENIX Security 2016 · 149 citations
- Reduced Cooling Redundancy: A New Security Vulnerability in a Hot Data CenterXing Gao, Zhang Xu, Haining Wang, Li Li et al.NDSS 2018 · 32 citations
- Why TLS is better without STARTTLS: A Security Analysis of STARTTLS in the Email ContextDamian Poddebniak, Fabian Ising, Hanno Böck, Sebastian SchinzelUSENIX Security 2021 · 25 citations
- Not that Simple: Email Delivery in the 21st CenturyFlorian Holzbauer, Johanna Ullrich, Martina Lindorfer, Tobias FiebigUSENIX ATC 2022 · 18 citations
- A Large-scale and Longitudinal Measurement Study of DKIM DeploymentChuhan Wang, Kaiwen Shen, Minglei Guo, Yuxuan Zhao et al.USENIX Security 2022
Related papers
- A Longitudinal and Comprehensive Study of the DANE Ecosystem in EmailHyeonmin Lee, Aniketh Gireesh, Roland van Rijswijk-Deij, Taekyoung Kwon et al.USENIX Security 2020
- TLS in the Wild: An Internet-wide Analysis of TLS-based Protocols for Electronic CommunicationRalph Holz, Johanna Amann, Olivier Mehani, Mohamed Ali Kâafar et al.NDSS 2016 · 117 citations
- Under the Hood of DANE Mismanagement in SMTPHyeonmin Lee, Md. Ishtiaq Ashiq, Moritz Müller, Roland van Rijswijk-Deij et al.USENIX Security 2022
- You've Got Report: Measurement and Security Implications of DMARC ReportingMd. Ishtiaq Ashiq, Weitong Li, Tobias Fiebig, Taejoong ChungUSENIX Security 2023
- FakeBehalf: Imperceptible Email Spoofing Attacks against the Delegation Mechanism in Email SystemsJinrui Ma, Lutong Chen, Kaiping Xue, Bo Luo et al.USENIX Security 2024 · 7 citations
