Skip to content
arrow_back
search
ISM-0572 policy ASD Information Security Manual (ISM)

Enable Opportunistic TLS for Email Server Encryption

Ensure email servers use encryption to protect emails sent over public networks.

record_voice_over

Plain language

This control is all about making sure your emails are encrypted when they travel over the internet. By enabling a feature called Opportunistic TLS on your email servers, you're ensuring that emails aren't easily intercepted or read by others. If this isn't set up, confidential information in emails could be exposed to hackers, leading to data breaches and loss of trust.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Opportunistic TLS encryption is enabled on email servers that make incoming or outgoing email connections over public network infrastructure.
policy ASD Information Security Manual (ISM) ISM-0572
priority_high

Why it matters

Without opportunistic TLS, emails could be intercepted over public networks, exposing sensitive data and undermining organisational trust.

settings

Operational notes

Ensure opportunistic TLS is enabled for inbound/outbound SMTP, use strong TLS settings, valid certificates, and monitor logs for failed TLS handshakes or downgrade attempts.

Mapping detail

Mapping

Direction

Controls