# SP-020 Email Transport Layer Security (TLS) Pattern

Status: published. Release 26.02. Modified 2026-02-06. Licence: CC BY-SA 4.0.

Scope: Security architecture for protecting email communication at the infrastructure level using gateway-to-gateway TLS encryption. Addresses opportunistic and enforced TLS modes, MTA authentication, certificate management, and monitoring for organisations with many business partner connections.
Use when: Apply this pattern as a baseline for all organisations that send and receive email over the internet. It is a transparent solution that requires no end-user interaction and provides immediate confidentiality improvement for email in transit.
Not when: This pattern is insufficient when email communication must be protected end-to-end from the sender's workstation to the recipient's workstation -- for example, when email content must remain confidential even from the organisation's own mail administrators or email outsourcer.

## Controls (8, NIST SP 800-53 ids)
- Critical (4): AU-06, IA-03, SC-09, SC-13
- Important (3): AC-04, SA-05, SC-07
- Standard (1): AC-03
- Withdrawn in SP 800-53 Rev 5: SC-09 (now in SC-08)

## What each critical control mitigates (4)
- AU-06 Audit Monitoring, Analysis, And Reporting: T-ET-003, T-ET-005, T-ET-007, T-ET-008
- IA-03 Device Identification And Authentication: T-ET-002, T-ET-004
- SC-09 Transmission Confidentiality: T-ET-001, T-ET-003, T-ET-006
- SC-13 Use Of Cryptography: T-ET-001, T-ET-002, T-ET-004, T-ET-007

## Threats and the controls that mitigate them (8)
- T-ET-001 Email Eavesdropping in Transit: SC-09, SC-13
- T-ET-002 Man-in-the-Middle Attack on SMTP Connection: IA-03, SC-13, SC-07
- T-ET-003 STARTTLS Downgrade Attack: SC-09, AU-06, AC-04
- T-ET-004 MTA Impersonation via Forged Certificate: IA-03, SC-13
- T-ET-005 Email Delivery Failure Due to Enforced TLS Misconfiguration: AU-06, SA-05
- T-ET-006 Third-Party Outsourcer Access to Decrypted Email: AC-04, SC-09, SA-05
- T-ET-007 TLS Stack Vulnerability Exploitation: SC-13, SC-07, AU-06
- T-ET-008 Unauthorised Modification of TLS Policy Configuration: AC-03, AU-06

## More
- The critical controls and what each mitigates, as JSON (a few KB): /api/v1/patterns/SP-020/crosswalk?emphasis=critical
- The same for every control, with its clauses in a framework: /api/v1/patterns/SP-020/crosswalk?framework={framework id}. Framework ids are listed in /llms.txt
- The pattern's prose, examples and references as JSON, 19 KB: /api/v1/patterns/SP-020
- Page for people: /patterns/sp-020/
- Related: SP-005 SOA Internal Service Usage Pattern; SP-006 Wireless Private Network Pattern; SP-007 Wireless Public Hotspot Pattern; SP-013 Data Security Pattern; SP-016 DMZ Module; SP-019 Secure Ad-Hoc File Exchange Pattern

This card, the API and the page are generated from one file. Checking one against another adds no evidence.
