{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,10]],"date-time":"2026-07-10T16:21:38Z","timestamp":1783700498514,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":43,"publisher":"ACM","funder":[{"name":"National Science Foundation","award":["CNS-2339378"],"award-info":[{"award-number":["CNS-2339378"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,10,28]]},"DOI":"10.1145\/3730567.3732916","type":"proceedings-article","created":{"date-parts":[[2025,10,15]],"date-time":"2025-10-15T17:39:24Z","timestamp":1760549964000},"page":"1-16","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["Unraveling the Complexities of MTA-STS Deployment and Management in Securing Email"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8282-6225","authenticated-orcid":false,"given":"Md. Ishtiaq","family":"Ashiq","sequence":"first","affiliation":[{"name":"Virginia Tech, Blacksburg, VA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0163-5134","authenticated-orcid":false,"given":"Tobias","family":"Fiebig","sequence":"additional","affiliation":[{"name":"Max-Planck Institute for Informatics, Saarbruecken, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4323-4080","authenticated-orcid":false,"given":"Taejoong","family":"Chung","sequence":"additional","affiliation":[{"name":"Virginia Tech, Blacksburg, VA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,10,15]]},"reference":[{"key":"e_1_3_2_2_1_1","unstructured":"Mail Operators' List. https:\/\/www.mailop.org\/."},{"key":"e_1_3_2_2_2_1","volume-title":"IETF","author":"D. E.","year":"2011","unstructured":"D. E. 3rd. Transport Layer Security (TLS) Extensions: Extension Definitions. RFC 6066, IETF, 2011."},{"key":"e_1_3_2_2_3_1","volume-title":"IETF","author":"Arends R.","year":"2005","unstructured":"R. Arends, R. Austein, M. Larson, D. Massey, and S. Rose. DNS Security Introduction and Requirements. RFC 4033, IETF, 2005. http:\/\/www.ietf.org\/rfc\/rfc4033.txt."},{"key":"e_1_3_2_2_4_1","volume-title":"IETF","author":"Arends R.","year":"2005","unstructured":"R. Arends, R. Austein, M. Larson, D. Massey, and S. Rose. Protocol Modifications for the DNS Security Extensions. RFC 4035, IETF, 2005. http:\/\/www.ietf.org\/rfc\/rfc4035.txt."},{"key":"e_1_3_2_2_5_1","volume-title":"IETF","author":"Arends R.","year":"2005","unstructured":"R. Arends, R. Austein, M. Larson, D. Massey, and S. Rose. Resource Records for the DNS Security Extensions. RFC 4034, IETF, 2005. http:\/\/www.ietf.org\/rfc\/rfc4034.txt."},{"key":"e_1_3_2_2_6_1","volume-title":"USENIX Security","author":"Blechschmidt B.","year":"2023","unstructured":"B. Blechschmidt and B. Stock. Extended Hell(o): A Comprehensive Large-Scale Study on Email Confidentiality and Integrity Mechanisms in the Wild. USENIX Security, 2023."},{"key":"e_1_3_2_2_7_1","volume-title":"IETF","author":"Barnes R.","year":"2019","unstructured":"R. Barnes, J. Hoffman-Andrews, D. McCarney, and J. Kasten. Automatic Certificate Management Environment (ACME). RFC 8555, IETF, 2019."},{"key":"e_1_3_2_2_8_1","volume-title":"IETF","author":"Cooper D.","year":"2008","unstructured":"D. Cooper, S. Santesson, S. Farrell, S. Boeyen, R. Housley, and W. Polk. Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile. RFC 5280, IETF, 2008. http:\/\/www.ietf.org\/rfc\/rfc5280.txt."},{"key":"e_1_3_2_2_9_1","volume-title":"USENIX Security","author":"Chen J.","year":"2020","unstructured":"J. Chen, V. Paxson, and J. Jiang. Composition kills: a case study of email sender authentication. USENIX Security, 2020."},{"key":"e_1_3_2_2_10_1","volume-title":"IMC","author":"Chung T.","year":"2017","unstructured":"T. Chung, R. van Rijswijk-Deij, D. Choffnes, A. Mislove, C. Wilson, D. Levin, and B. M. Maggs. Understanding the Role of Registrars in DNSSEC Deployment. IMC, 2017."},{"key":"e_1_3_2_2_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243794"},{"key":"e_1_3_2_2_12_1","volume-title":"IETF","author":"Dukhovni V.","year":"2015","unstructured":"V. Dukhovni and W. Hardaker. The DNS-Based Authentication of Named Entities (DANE) Protocol: Updates and Operational Guidance. RFC 7671, IETF, 2015."},{"key":"e_1_3_2_2_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/2815675.2815695"},{"key":"e_1_3_2_2_14_1","unstructured":"DNSSEC deployment in Sweden. https:\/\/archive.icann.org\/meetings\/london2014\/en\/schedule\/wed-dnssec\/presentation-dnssec-deployment-sweden-25jun14-en.pdf."},{"key":"e_1_3_2_2_15_1","unstructured":"Enhancing mail flow with MTA-STS. https:\/\/learn.microsoft.com\/en-us\/purview\/enhancing-mail-flow-with-mta-sts."},{"key":"e_1_3_2_2_16_1","volume-title":"CCS","author":"Foster I.","year":"2015","unstructured":"I. Foster, J. Larson, M. Masich, A. C. Snoeren, S. Savage, and K. Levchenko. Security by Any Other Name: On the Effectiveness of Provider Based Email Security. CCS, 2015."},{"key":"e_1_3_2_2_17_1","volume-title":"USENIX ATC","author":"Holzbauer F.","year":"2022","unstructured":"F. Holzbauer, J. Ullrich, M. Lindorfer, and T. Fiebig. Not that Simple: Email Delivery in the 21st Century. USENIX ATC, 2022."},{"key":"e_1_3_2_2_18_1","volume-title":"Measuring the use of DNSSEC","author":"Huston G.","year":"2023","unstructured":"G. Huston. Measuring the use of DNSSEC. 2023. https:\/\/blog.apnic.net\/2023\/09\/18\/measuring-the-use-of-dnssec\/."},{"key":"e_1_3_2_2_19_1","volume-title":"USENIX Security","author":"Hu H.","year":"2018","unstructured":"H. Hu and G. Wang. End-to-End Measurements of Email Spoofing Attacks. USENIX Security, 2018."},{"key":"e_1_3_2_2_20_1","volume-title":"IEFT","author":"Hoffman P.","year":"2002","unstructured":"P. Hoffman. SMTP Service Extension for Secure SMTP over Transport Layer Security. IETF RFC 3207, IEFT, 2002."},{"key":"e_1_3_2_2_21_1","volume-title":"NDSS","author":"Holz R.","year":"2015","unstructured":"R. Holz, J. Amann, O. Mehani, M. Wachs, and M. A. Kaafar. TLS in the wild: an Internet-wide analysis of TLS-based protocols for electronic communication. NDSS, 2015."},{"key":"e_1_3_2_2_22_1","unstructured":"Increase email security with MTA-STS and TLS reporting About MTA-STS and TLS reporting. https:\/\/support.google.com\/a\/answer\/9261504?hl=en."},{"key":"e_1_3_2_2_23_1","volume-title":"USENIX Security","author":"Lee H.","year":"2022","unstructured":"H. Lee, M. I. Ashiq, M. Muller, R. van Rijswijk-Deij, T. Kwon, and T. Chung. Under the Hood of DANE Mismanagement in SMTP. USENIX Security, 2022."},{"key":"e_1_3_2_2_24_1","volume-title":"USENIX Security","author":"Lee H.","year":"2020","unstructured":"H. Lee, A. Girish, R. van Rijswijk-Deij, T. T. Kwon, and T. Chung. A Longitudinal and Comprehensive Study of the DANE Ecosystem in Email. USENIX Security, 2020."},{"key":"e_1_3_2_2_25_1","unstructured":"Levenshtein distance. https:\/\/xlinux.nist.gov\/dads\/HTML\/Levenshtein.html."},{"key":"e_1_3_2_2_26_1","volume-title":"IETF","author":"Margolis D.","year":"2018","unstructured":"D. Margolis, M. Risher, B. Ramakrishnan, A. Brotman, and a. J. Jones. SMTP MTA Strict Transport Security (MTA-STS). RFC 8461, IETF, 2018."},{"key":"e_1_3_2_2_27_1","first-page":"8460","volume":"8460","author":"Margolis D.","year":"2018","unstructured":"D. Margolis, A. Brotman, B. Ramakrishnan, J. Jones, and M. Risher. SMTP TLS Reporting. RFC 8460, 8460, RFC Editor, 2018.","journal-title":"SMTP TLS Reporting. RFC"},{"key":"e_1_3_2_2_28_1","unstructured":"MTA-STS Overrides DANE. https:\/\/github.com\/Snawoot\/postfix-mta-sts-resolver\/issues\/67."},{"key":"e_1_3_2_2_29_1","unstructured":"Mail.com MTA-STS Policy. https:\/\/mta-sts.mail.com\/.well-known\/mta-sts.txt."},{"key":"e_1_3_2_2_30_1","unstructured":"Modern Email Security Standards for EU (MESSEU). messeu@sys4.de."},{"key":"e_1_3_2_2_31_1","unstructured":"North American Network Operators' Group. https:\/\/www.nanog.org\/."},{"key":"e_1_3_2_2_32_1","volume-title":"USENIX Security","author":"Poddebniak D.","year":"2021","unstructured":"D. Poddebniak, F. Ising, H. B\u00f6ck, and S. Schinzel. Why TLS is better without STARTTLS: A Security Analysis of STARTTLS in the Email Context. USENIX Security, 2021."},{"key":"e_1_3_2_2_33_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23386"},{"key":"e_1_3_2_2_34_1","unstructured":"Porkbun LLC. https:\/\/porkbun.com\/."},{"key":"e_1_3_2_2_35_1","unstructured":"Postfix. http:\/\/www.postfix.org\/."},{"key":"e_1_3_2_2_36_1","unstructured":"Potential Risks with MTA-STS Usage? https:\/\/support.dmarcreport.com\/support\/solutions\/articles\/5000885320-potential-risks-with-mta-sts-usage-."},{"key":"e_1_3_2_2_37_1","volume-title":"A summary of survey methodology best practices for security and privacy researchers","author":"Redmiles E.","year":"2017","unstructured":"E. Redmiles, Y. Acar, S. Fahl, and M. Mazurek. A summary of survey methodology best practices for security and privacy researchers. 2017. https:\/\/drum.lib.umd.edu\/items\/683d78b0-a0e3-4fae-9c93-b75aae4ad11b."},{"key":"e_1_3_2_2_38_1","volume-title":"NDSS","author":"Stock B.","year":"2018","unstructured":"B. Stock, G. Pellegrino, F. Li, M. Backes, and C. Rossow. Didn't You Hear Me? \u2014 Towards More Successful Web Vulnerability Notifications. NDSS, 2018."},{"key":"e_1_3_2_2_39_1","volume-title":"DIMVA","author":"Tatang D.","year":"2021","unstructured":"D. Tatang, F. Zettl, and T. Holz. A First Large-Scale Analysis on Usage of MTA-STS. DIMVA, 2021."},{"key":"e_1_3_2_2_40_1","unstructured":"TLD Distribution. https:\/\/domainnamestat.com\/statistics\/tld\/others."},{"key":"e_1_3_2_2_41_1","unstructured":"The current state of SMTP STARTTLS deployment. https:\/\/www.facebook.com\/notes\/protect-the-graph\/the-current-state-of-smtp-starttls-deployment\/1453015901605223\/."},{"key":"e_1_3_2_2_42_1","unstructured":"What is greylisting and how does it work? https:\/\/www.mail.com\/blog\/posts\/what-is-greylisting\/33\/."},{"key":"e_1_3_2_2_43_1","unstructured":"Yahoo! Mail MTA-STS. https:\/\/mta-sts.yahoo.com\/.well-known\/mta-sts.txt."}],"event":{"name":"IMC '25:ACM Internet Measurement Conference","location":"Madison WI USA","sponsor":["SIGMETRICS ACM Special Interest Group on Measurement and Evaluation","SIGCOMM ACM Special Interest Group on Data Communication"]},"container-title":["Proceedings of the 2025 ACM Internet Measurement Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3730567.3732916","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,21]],"date-time":"2025-11-21T15:30:57Z","timestamp":1763739057000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3730567.3732916"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,15]]},"references-count":43,"alternative-id":["10.1145\/3730567.3732916","10.1145\/3730567"],"URL":"https:\/\/doi.org\/10.1145\/3730567.3732916","relation":{},"subject":[],"published":{"date-parts":[[2025,10,15]]},"assertion":[{"value":"2025-10-15","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}