Feature Request: Include TLS Cipher Suites and eccurve information in Email Headers
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 35/100
- Issue 类型
- 功能
- 描述清晰度
- 基本清楚
- 活跃度
- 停滞
- 技术栈
- go
- 领域
- backend, networking, security
调研方向
未指定文件、测试或入口点。先定位传入 SMTP TLS 的处理逻辑以及构建 Received headers 的代码,然后确定协商出的 cipher 和 elliptic-curve 详细信息是如何暴露的。完成的标准是:传入 headers 包含所请求的 TLS 详细信息,并且相关的现有测试验证了该行为。
由索引模型根据 Issue 内容生成。
描述
Use case
Displaying information such as the TLS cipher suites and elliptic curves (ECC) negotiated with other SMTP servers in email headers can help us study and understand the adoption of state-of-the-art cryptography in transport. This information can be invaluable for optimizing our configuration over time to ensure stronger and more secure transport over TLS.
How it currently looks in Maddy's and in email headers of other servers including popular service providers
Maddy [for incoming from Fastmail]:
Received: from fout-b3-smtp.messagingengine.com
(fout-b3-smtp.messagingengine.com [202.12.124.146]) by
mail.nixsanctuary.com (envelope-sender [email protected]) with ESMTPS id
4f52b211; Wed, 07 Jan 2026 12:45:19 +0900
Maddy [for incoming from Gmail]:
Received: from mail-lj1-x236.google.com (mail-lj1-x236.google.com
[2a00:1450:4864:20::236]) by mail.nixsanctuary.com (envelope-sender
[email protected]) with ESMTPS id a7a57637; Sun, 04 Jan 2026 23:01:51
+0900
Proton [for incoming from Maddy]:
Received: from mail.nixsanctuary.com (mail.nixsanctuary.com [158.51.x.x]) (using
TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No
client certificate requested) by mailinosl103.protonmail.ch (Postfix) with ESMTPS id
4dmF320HY3z3P for [email protected]; Wed,
7 Jan 2026 04:11:25 +0000 (UTC)
Gmail [for incoming from Maddy]:
Received: from mail.nixsanctuary.com (mail.nixsanctuary.com. [2602:fd6f💯6a::a])
by mx.google.com with ESMTPS id 41be03b00d2f7-c4cbdd5b9c9si5705685a12.100.2026.01.06.20.15.08
for [email protected]
(version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128);
Tue, 06 Jan 2026 20:15:11 -0800 (PST)
Hetzner Exim Server [for incoming from Maddy]:
Received: from mail.nixsanctuary.com ([2602:fd6f❌x::x])
by www186.your-server.de with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384
(Exim 4.96.2)
(envelope-from [email protected])
id 1vciUD-000LPj-0M
for [email protected];
Mon, 05 Jan 2026 12:10:59 +0100
Microsoft's Outlook [for incoming from Maddy]:
Received: from mail.nixsanctuary.com (2602:fd6f❌x::x) by
DU2PEPF00028D00.mail.protection.outlook.com (2603:10a6:18:3::6b8) with
Microsoft SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id
15.20.9478.4 via Frontend Transport; Wed, 7 Jan 2026 04:15:10 +0000
Your idea for a solution
I really like how Proton displays TLS cipher suites and eccurve information in email headers.
TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256)
Maybe we can implement the same in Maddy's email headers for incoming emails.
Thank you!
Regards.
- 主要语言
- Go
- 星标
- 6.1k
- 派生
- 329
- 平均合并
- 23 天 6 小时
- 30 天内合并 PR
- 1
环境准备
- 提供 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
foxcpp/maddy 的其他 Issue
-
ready-for-release
难度 1/5 1 小时以内 新手友好度 65/100
-
难度 3/5 1-2 天 新手友好度 55/100
-
难度 2/5 1-3 小时 新手友好度 25/100
-
bug
难度 3/5 1-2 天 新手友好度 55/100
-
No usable MXs when attempting delivery to SMTP server smtp.libero.it可能重新可做 @foxcpp 于 148 天前认领,目前没有进行中的 PR。 未关闭bug invalid
相似的 Issue
-
bug frontend good first issue
难度 2/5 1-3 小时 新手友好度 86/100
维护者通常 1 天内回复
-
trust: update-propagation-directive requires developer mode while add and remove do not可能已有人在做 @bhuvan-somisetty 今天认领。 未关闭
难度 2/5 1-3 小时 新手友好度 72/100
维护者通常 2 天内回复
-
难度 1/5 1 小时以内 新手友好度 82/100
oalders/clodhopper#133 ·
-
难度 2/5 1-3 小时 新手友好度 62/100
peasant-labs/peasant#596 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 78/100
hatchet-dev/hatchet#5179 ·
维护者通常 1 天内回复