<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>mail server Archives - OVHcloud Blog</title>
	<atom:link href="https://blog.ovhcloud.com/tag/mail-server/feed/" rel="self" type="application/rss+xml" />
	<link>https://blog.ovhcloud.com/tag/mail-server/</link>
	<description>Innovation for Freedom</description>
	<lastBuildDate>Mon, 19 May 2025 11:49:05 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://blog.ovhcloud.com/wp-content/uploads/2019/07/cropped-cropped-nouveau-logo-ovh-rebranding-32x32.gif</url>
	<title>mail server Archives - OVHcloud Blog</title>
	<link>https://blog.ovhcloud.com/tag/mail-server/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Security of Exchange services: TLS update and best practices</title>
		<link>https://blog.ovhcloud.com/security-of-exchange-services-tls-update-and-best-practices/</link>
		
		<dc:creator><![CDATA[Fabien Bouvet]]></dc:creator>
		<pubDate>Wed, 14 May 2025 14:28:19 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Web Cloud]]></category>
		<category><![CDATA[exchange]]></category>
		<category><![CDATA[mail server]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[TLS]]></category>
		<guid isPermaLink="false">https://blog.ovhcloud.com/?p=28806</guid>

					<description><![CDATA[Introduction We at OVHcloud are committed to providing secure and professional email services that meet the latest industry standards. To boost security, we’re disabling TLS 1.0 and 1.1 protocols on our Exchange solutions, in line with international standards. Are you using a recent and updated email client? You don’t need to do anything; all email [&#8230;]<img src="//blog.ovhcloud.com/wp-content/plugins/matomo/app/matomo.php?idsite=1&amp;rec=1&amp;url=https%3A%2F%2Fblog.ovhcloud.com%2Fsecurity-of-exchange-services-tls-update-and-best-practices%2F&amp;action_name=Security%20of%20Exchange%20services%3A%20TLS%20update%20and%20best%20practices&amp;urlref=https%3A%2F%2Fblog.ovhcloud.com%2Ffeed%2F" style="border:0;width:0;height:0" width="0" height="0" alt="" />]]></description>
										<content:encoded><![CDATA[
<h2 class="wp-block-heading">Introduction</h2>



<p>We at OVHcloud are committed to providing secure and professional email services that meet the latest industry standards. To boost security, we’re disabling TLS 1.0 and 1.1 protocols on our Exchange solutions, in line with international standards.</p>



<p>Are you using a recent and updated email client? <strong>You don’t need to do anything</strong>; all email clients have already been updated and support the latest TLS (1.2). Action is needed only if you’re running a very old version.</p>



<p>We’re ditching older TLS versions and stepping up security across OVHcloud Exchange services. This blog will cover what’s changing and the measures we’re taking to keep your data safe.&nbsp;</p>



<h2 class="wp-block-heading">TLS 1.0 and 1.1 deprecations</h2>



<p>To improve security and service quality, we’re disabling TLS 1.0 and 1.1 on all our OVHcloud Exchange solutions.<br>While some Microsoft systems may still use them, these TLS versions have security holes and were officially deprecated in 2021. Plus, they are already disabled on most Microsoft services, including several Exchange options.</p>



<ul class="wp-block-list"></ul>



<h2 class="wp-block-heading">Single-standard supported protocols</h2>



<p>Our goal is to apply the same configuration across all infrastructure. Since these protocols are already inactive on most of our servers, updating will standardise our setups and elevate security.</p>



<p><strong>Supported ciphers</strong></p>



<p>We’re also making adjustments to ciphers, so only the following will be supported:</p>



<ul class="wp-block-list">
<li><a href="https://ciphersuite.info/cs/TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384/" data-wpel-link="external" target="_blank" rel="nofollow external noopener noreferrer">&#8220;TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384</a>&#8220;</li>



<li>&#8220;<a href="https://ciphersuite.info/cs/TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256/" data-wpel-link="external" target="_blank" rel="nofollow external noopener noreferrer">TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256</a>&#8220;</li>



<li><a href="https://ciphersuite.info/cs/TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384/" data-wpel-link="external" target="_blank" rel="nofollow external noopener noreferrer">&#8220;TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384</a>&#8220;</li>



<li>&#8220;<a href="https://ciphersuite.info/cs/TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256/" data-wpel-link="external" target="_blank" rel="nofollow external noopener noreferrer">TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256</a>&#8220;</li>
</ul>



<p>Keep in mind, only older operating systems (outdated printers or unsupported systems) might have issues.</p>



<p>Customers can use the <a href="https://clienttest.ssllabs.com:8443/ssltest/viewMyClient.html" data-wpel-link="external" target="_blank" rel="nofollow external noopener noreferrer">SSL Labs tool</a> to see which encryption protocols their machine supports.</p>



<p>We use the best practices from the 2020 version 1.6 guides, see <a href="https://github.com/ssllabs/research/wiki/SSL-and-TLS-Deployment-Best-Practices#version-16-15-january-2020" data-wpel-link="external" target="_blank" rel="nofollow external noopener noreferrer">here</a>.</p>



<ul class="wp-block-list"></ul>



<h2 class="wp-block-heading">HSTS protocol activation</h2>



<p>We also use the HTTP Strict Transport Security (HSTS) protocol to keep connections between customers and OVHcloud Exchange servers secure.</p>



<p>This protocol helps to:</p>



<ul class="wp-block-list">
<li>enforce TLS usage by blocking unencrypted connections;</li>



<li>protect against Man-in-the-Middle (MITM) attacks and block redirects/downgrades to unsecured HTTPS connections;</li>



<li>automatically switch from HTTP to HTTPS for higher user security.</li>
</ul>



<p>OVHcloud customers won’t notice this update, which will be automatic—no action needed.</p>



<ul class="wp-block-list"></ul>



<h2 class="wp-block-heading">Exchange update management</h2>



<p><strong>Monthly update process</strong></p>



<p>Microsoft releases security updates for Microsoft Exchange Server every Patch Tuesday. OVHcloud applies these patches every month to bolster security for its Exchange solutions.</p>



<p><strong>Our update process</strong></p>



<ul class="wp-block-list">
<li><strong>The 2<sup>nd</sup> Tuesday of each month:</strong> Microsoft update release.</li>



<li><strong>Microsoft partnership:</strong> Thanks to our strong partnership, we have access to detailed information on patches and product releases. This gives us a better idea of how much work the next update will involve, so we can plan ahead.</li>



<li><strong>Vulnerability severity analysis:</strong>
<ul class="wp-block-list">
<li><strong>Moderate risk</strong> → Maintenance is planned and staggered to minimise service disruptions.</li>



<li><strong>High risk</strong> → A dedicated team starts maintenance right after the patches are released.</li>
</ul>
</li>
</ul>



<p><strong>Update notifications</strong></p>



<ul class="wp-block-list">
<li>PRIVATE solution customers are notified at the start and end of updates.</li>



<li>RESELLER, HOSTED, MXPLAN, TRUSTED, and EMAILPRO customers can use Exchange’ clustering to track maintenance progress on the <a href="https://web-cloud.status-ovhcloud.com/" data-wpel-link="external" target="_blank" rel="nofollow external noopener noreferrer">OVHcloud status page</a>.</li>
</ul>



<figure class="wp-block-image aligncenter size-large is-resized"><img fetchpriority="high" decoding="async" width="1024" height="399" src="https://blog.ovhcloud.com/wp-content/uploads/2025/05/vulnerability-management-of-PU.MS_-1024x399.png" alt="" class="wp-image-28861" style="width:828px;height:auto" srcset="https://blog.ovhcloud.com/wp-content/uploads/2025/05/vulnerability-management-of-PU.MS_-1024x399.png 1024w, https://blog.ovhcloud.com/wp-content/uploads/2025/05/vulnerability-management-of-PU.MS_-300x117.png 300w, https://blog.ovhcloud.com/wp-content/uploads/2025/05/vulnerability-management-of-PU.MS_-768x299.png 768w, https://blog.ovhcloud.com/wp-content/uploads/2025/05/vulnerability-management-of-PU.MS_-1536x599.png 1536w, https://blog.ovhcloud.com/wp-content/uploads/2025/05/vulnerability-management-of-PU.MS_.png 1639w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<h2 class="wp-block-heading">Real-Time monitoring and protection</h2>



<p>We use several monitoring tools, developed in-house or provided by third-party vendors, to:</p>



<ul class="wp-block-list">
<li>monitor the exposure of OVHcloud Exchange services on the internet;</li>



<li>detect vulnerabilities and unusual activity in real time;</li>



<li>generate alerts and reports for instant analysis and troubleshooting.</li>
</ul>



<h2 class="wp-block-heading">Advanced spam protection</h2>



<p>Our OVHcloud Exchange solutions include a European anti-spam system that filters messages before they reach your inbox.</p>



<p>Benefits of spam filtering:</p>



<ul class="wp-block-list">
<li>advanced detection of fraudulent and phishing emails;</li>



<li>smart filtering based on machine learning;</li>



<li>significant decrease in spam and malicious emails.</li>
</ul>



<h2 class="wp-block-heading">HTTP request management update</h2>



<p><strong>Host Header Removal</strong></p>



<p>We’re currently fixing a server issue related to incorrect HTTP Host header usage. An invalid HTTP host header in a web request causes the server to immediately abort the request—this is specific to HTTP 1.0.</p>



<p><strong>Server Header Removal</strong></p>



<p>The HTTP server stops sending the header.</p>



<h2 class="wp-block-heading">To recap…</h2>



<p>We’re upgrading OVHcloud Exchange security by phasing out less secure TLS 1.0/1.1 protocols, bringing it in line with internationals security standards.<br>Regular updates, HSTS activation, continuous monitoring, and advanced anti-spam protection guarantee a secure, high-performance Exchange environment for all our customers.</p>



<p>Got questions about this update? Reach out to our <a href="https://www.ovhcloud.com/en-gb/contact/" data-wpel-link="external" target="_blank" rel="nofollow external noopener noreferrer">technical support</a> team.</p>



<figure class="wp-block-image aligncenter size-full"><img decoding="async" width="371" height="353" src="https://blog.ovhcloud.com/wp-content/uploads/2025/05/image-2.png" alt="" class="wp-image-28811" srcset="https://blog.ovhcloud.com/wp-content/uploads/2025/05/image-2.png 371w, https://blog.ovhcloud.com/wp-content/uploads/2025/05/image-2-300x285.png 300w" sizes="(max-width: 371px) 100vw, 371px" /></figure>
<img decoding="async" src="//blog.ovhcloud.com/wp-content/plugins/matomo/app/matomo.php?idsite=1&amp;rec=1&amp;url=https%3A%2F%2Fblog.ovhcloud.com%2Fsecurity-of-exchange-services-tls-update-and-best-practices%2F&amp;action_name=Security%20of%20Exchange%20services%3A%20TLS%20update%20and%20best%20practices&amp;urlref=https%3A%2F%2Fblog.ovhcloud.com%2Ffeed%2F" style="border:0;width:0;height:0" width="0" height="0" alt="" />]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
