On Thu, Mar 14, 2019 at 10:27 AM Nico Williams <n...@cryptonector.com>
wrote:

>   | 4.  Policy Validation
>   |
>   |    When sending to an MX at a domain for which the sender has a valid
>   |    and non-expired MTA-STS Policy, a Sending MTA honoring MTA-STS MUST
>                                        ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
>                                                      ^^^^^^^^
>   |    check whether:
>   |
>   |    [...]
>   |
>   | 5.  Policy Application
>   |
>   |    When sending to an MX at a domain for which the sender has a valid,
>   |    non-expired MTA-STS Policy, a Sending MTA honoring MTA-STS applies
>                                    ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
>                                                  ^^^^^^^^
>   |    the result of a policy validation failure in one of two ways,
>   |    depending on the value of the policy "mode" field:
>   |
>   |    [...]
>
> How does this not allow a sending MTA to... not honor MTA-STS?
>

It's allowed to not *generally* honor STS, but this text does not have any
provision for just ignoring it for some messages. Any other reading seems
extremely strained.

-Ekr


> Nico
> --
>
_______________________________________________
Uta mailing list
Uta@ietf.org
https://www.ietf.org/mailman/listinfo/uta

Reply via email to