www.noreply.org :: TLS
 
 

SMTP - TLS

Transport Layer Security (similar to SSL) brings forward secrecy to Internet Email by encrypting SMTP traffic.

Even though usual remailer mail is already encrypted, TLS adds security because the key used in TLS sessions usually is ephemeral - i.e. it only exists for seconds and is destroyed immediatly after use. Whether or not short-lived keys are used depends on the cipher suite chosen. (The EDH (Ephemeral Diffie-Hellman) ciphers use ephemeral keys.)

Ephemeral keys make it impossible to decrypt data which was eavesdropped at one time by compromising a remailer's key later.

Since remailer keys are valid for weeks, sometimes years, this makes remailing more secure.

The submission column indicates that a mailserver acceps mails on port 587 (submission). The smtps column that it accepts SSL connections on port 465 (smtps) for use with stunnel and similar. Some hosts also accept normal connections on port 2525 - this is indicated in the column 2525. Please note that some hosts may enforce the use of TLS on the submission port.

Stunnel can do STARTTLS using -n smtp or with protocol = smtp in your config file, depending on your version.

See the Encrypted Email - TLS/SSL on banasplit for a howto on using stunnel on Windows with Quicksilver and JBN2.

remailermail exchangerpriorityTLSsubmissionsmtps2525error/warning
antani <mixmaster@firenze.linux.it>
  mail.firenze.linux.it 5 no no no no
austria <mixmaster@remailer.privacy.at>
  remailer.privacy.at 0 YES
DHE-RSA-AES256-SHA
no no no
banana <banana@mixmaster.mixmin.net>
  drooper.mixmin.net 10 YES
DHE-RSA-AES256-SHA
yes yes
DHE-RSA-AES256-SHA
yes
borked <remailer@pseudo.borked.net>
  pseudo.borked.net 10 no no no no
bunker <mixmaster@mixmaster.thebunker.net>
  mixmaster.thebunker.net 0 no no no no
citrus <mix@outel.org>
  mail.outel.org 5 no no no no
cripto <anon@ecn.org>
  www.ecn.org 10 YES
DHE-RSA-AES256-SHA
yes yes
DHE-RSA-AES256-SHA
no
cside <cside@cside.dyndns.org>
  cside.dyndns.org 0 no no no no
cyberiad <mixmaster@remailer.cyberiade.it>
  mail.cyberiade.it 0 YES
DHE-RSA-AES256-SHA
yes yes
DHE-RSA-AES256-SHA
no
devurandom <mixmaster@anonymitaet-im-inter.net>
  mail.anonymitaet-im-inter.net 10 no no no no
dizum <remailer@dizum.com>
  smtp.zedz.net 10 YES
DHE-RSA-AES256-SHA
no no no
eelbash <eelbash@teksavvy.com>
  ironport.teksavvy.com 1 no no no no
  ironport.teksavvy.com 5 no no no no
  ironport.teksavvy.com 10 no no no no
  ironport.teksavvy.com 20 no no no no
eurovibes <mixmaster@eurovibes.org>
  mail.eurovibes.org 50 YES
DHE-RSA-AES256-SHA
no no no
frell <godot@remailer.frell.eu.org>
  mail2.frell.eu.org 10 YES
DHE-RSA-AES256-SHA
yes yes
DHE-RSA-AES256-SHA
yes
  mail1.frell.theremailer.net 30 YES
DHE-RSA-AES256-SHA
yes yes
DHE-RSA-AES256-SHA
yes
george <mix@mixmaster.it>
  mixmaster.it 0 YES
DHE-RSA-AES256-SHA
no no no
gpfc <mixmaster@gpftor3.privacyfoundation.de>
  gpftor3.privacyfoundation.de 0 no no no no
hermetix <mix@hermetix.org>
  mail.hermetix.org 10 YES
DHE-RSA-AES256-SHA
no no no
kroken <remailer@kroken.dynalias.com>
  rooty.uni-boeblingen.de 10 YES
DHE-RSA-AES256-SHA
no no no
kulin <remailer@reece.net.au>
  mx3.netregistry.net 10 no no no no
  mx2.netregistry.net 20 no no no no
lulunga <mixmaster@remailer.cypherpunks.to>
  remailer.cypherpunks.to 100 YES
DHE-RSA-AES256-SHA
no no no
nightmix <nightmix@rocketmail.com>
  e.mx.mail.yahoo.com 1 no no no no
  f.mx.mail.yahoo.com 1 N/A no no no f.mx.mail.yahoo.com has round robin A records
  Code is 421 and not 220 (Message from (86.59.118.153) temporarily deferred - 4.16.50. Please refer to http://help.yahoo.com/help/us/mail/defer/defer-06.html )
  g.mx.mail.yahoo.com 1 N/A no no no g.mx.mail.yahoo.com has round robin A records
  Code is 421 and not 220 (Message from (86.59.118.153) temporarily deferred - 4.16.50. Please refer to http://help.yahoo.com/help/us/mail/defer/defer-06.html )
  a.mx.mail.yahoo.com 1 N/A no no no Code is 421 and not 220 (Message from (86.59.118.153) temporarily deferred - 4.16.50. Please refer to http://help.yahoo.com/help/us/mail/defer/defer-06.html )
  b.mx.mail.yahoo.com 1 no no no no
  c.mx.mail.yahoo.com 1 N/A no no no c.mx.mail.yahoo.com has round robin A records
  Cannot connect: Timeout
  d.mx.mail.yahoo.com 1 no no no no
panta <remailer@panta-rhei.eu.org>
  remailer-debian.panta-rhei.eu.org 10 YES
DHE-RSA-AES256-SHA
yes yes
DHE-RSA-AES256-SHA
yes
paranoia <mixmaster@remailer.paranoici.org>
  remailer.paranoici.org 10 N/A no no no Cannot connect: Timeout
  mx5.investici.org 50 YES
DHE-RSA-AES256-SHA
yes yes
DHE-RSA-AES256-SHA
no
  mx1.investici.org 50 YES
DHE-RSA-AES256-SHA
yes yes
DHE-RSA-AES256-SHA
no
  mx2.investici.org 50 YES
DHE-RSA-AES256-SHA
yes yes
DHE-RSA-AES256-SHA
no
  mx4.investici.org 50 YES
DHE-RSA-AES256-SHA
yes yes
DHE-RSA-AES256-SHA
no
pboxmix <mixmaster@pboxmix.winstonsmith.info>
  pboxmix.winstonsmith.info 5 YES
DHE-RSA-AES256-SHA
no no no
senshi <senshiremailer@gmx.de>
  mx0.gmx.de 10 no no no no
  mx0.gmx.net 10 no no no no
slow <slowmix@mixmaster.mixmin.net>
  drooper.mixmin.net 10 YES
DHE-RSA-AES256-SHA
yes yes
DHE-RSA-AES256-SHA
yes
starwars <mixmaster@tatooine.homelinux.net>
  tatooine.homelinux.net 0 N/A no no no Cannot connect: Timeout

Built at Wed Nov 19 22:30:41 2008.

 
web@palfrader.org - Valid HTML 4.01!