Potential security issue: SMTP server at mx.zohomail.com does not support TLS
Dear support,
I was just checking the behavior of the SMTP server at mx.zohomail.com via http://www.checktls.com and realized that it does not support TLS, i.e. mails are sent unencrypted over the wire. In principal, any network device between a foreign MTA and your MTA sees your user's incoming mails in plain text.
Other mail service providers (such as googlemail) in fact do support TLS encryption between MTAs. This is for a reason and I am severely concerned by the fact that you don't.
I would like to see a statement from your side, helping me to understand your reasoning not to support TLS for incoming mails. Is it planned for the future?
Thanks,
Jan-Philip