Email core draft stuck on MUST to accept cleartext SMTP
Last Call on the IETF applicability statement reopenes a fight over whether receivers must be able to take mail without TLS.
The IETF’s core email applicability statement is in Last Call with a live dispute over a single normative line: that SMTP receivers MUST be able to accept mail with or without confidentiality.
The draft (draft-ietf-emailcore-as) aims to say how modern SMTP should be used. After earlier revisions, the contested sentence still requires receivers to be able to take unprotected traffic, then adds that what any party does in a given case is local policy. That combination drew a DISCUSS from Roman Danyliw asking why receivers cannot require over-the-wire confidentiality, and fresh objections on the Last Call list.
Critics including Rob Sayre, Eric Rescorla, Martin Thomson, and Richard Barnes want the MUST gone. They argue it is unclear whether it binds code or deployments, and that either reading is a problem: it either forces implementations to keep a cleartext path or tells operators they cannot refuse unprotected mail. Thomson floated replacement text that would require senders to use confidentiality when the receiver offers it, leave acceptance of unprotected mail to local policy, and point at Security Considerations without new normative rules there. Rescorla and Barnes backed dropping the mandate rather than writing a new one.
Operators and long-time mail contributors push the other way. John Levine said large providers have been in the work throughout, still accept mail with or without STARTTLS, and will not stop: rejecting cleartext would drop mail people want and, he warned, send users to ask friends whether they use Telegram or WhatsApp instead. Eliot Lear and others said ignoring that operational reality and the long tail would discredit the document. George Michaelson, noting the draft is at revision 30 and positions have not moved for months, urged shipping with the insecure option left open and taking a harder confidentiality drive in a later effort.
Viktor Dukhovni stressed the text only requires the ability to accept cleartext, not a default to do so, and that opportunistic STARTTLS alone still yields to active attack without stronger authenticaton such as DANE. The split is not over whether TLS is good practice. It is over whether an applicability statement should freeze today’s interoperability habit as a MUST, or stay silent so operators who want to require confidentiality are not told they are out of conformance.