Mail transport security foundation deployed
The replacement mail platform has completed a production security review, gained a monitored MTA-STS policy, and had its DNSSEC chain independently validated.
Mail platform review
The replacement SCComp mail host has completed a focused production security review covering encrypted transport, authentication boundaries, relay controls, abuse protection, firewall policy, service health, certificate status, update handling, queues, and operational logs.
Transport policy
An MTA-STS policy is now configured in testing mode for `sccomp.us`. It identifies `mail.sccomp.us` as the authorized inbound mail exchanger and uses a short one-day lifetime during the observation stage. Testing mode lets SCComp validate compatibility and reporting before moving to enforcement.
Verified protections
• Modern TLS is required for mail transport and authenticated submission.
• Plaintext authentication is refused outside encryption.
• Mail relay restrictions and SMTP protocol-abuse defenses are active.
• Mailcow netfilter and Rspamd provide automated abuse and spam controls.
• Host firewalling uses a default-deny inbound policy.
• The production queue was empty and core containers were healthy during validation.
• A complete native backup was captured before the policy change.
DNS security
The `sccomp.us` DNSSEC chain now validates through independent public resolvers. Remaining DNS work will publish MTA-STS discovery, TLS failure reporting, aggregate sender-policy reporting, and a restrictive certificate-authority policy. Sender rejection policies will be tightened only after report data confirms every legitimate sender is aligned.
Certificate activation
After the DNS records propagated, Mailcow issued and deployed a new Let's Encrypt certificate covering the dedicated MTA-STS hostname. The public policy can now be retrieved with normal certificate-chain and hostname verification. Mail transport policy remains in testing mode while operational reports are collected before enforcement.
Enforcement enabled
After stable production operation and successful certificate/DNS validation, SCComp promoted MTA-STS from testing to enforcement. Compliant sending servers are now instructed to deliver mail only to the authorized `mail.sccomp.us` exchanger over authenticated TLS. The initial enforcement policy uses a 24-hour lifetime to retain a controlled rollback window.