Skip to main content

#TLSemail 

#TLS 1.0 Disablement 

 

Hello,

 

We're continuing to receive the TLS Disablement email notification despite confirming that our email server uses a higher version (we use Gmail which uses TLS 1.2). Is there a reason we are continuing to receive these emails and notifications or some next steps we need to take? I'm concerned because the email states: "You are receiving this communication because you are the admin of a Salesforce org that is still either sending or receiving emails from your Salesforce org using the TLS 1.0 encryption protocol." and yet we only send outbound messages through our Gmail server which already meets the new standard. 

 

Please clarify. Thank you!

 

Sarah 

20 commenti
  1. 5 mar 2018, 20:58
    @Lyn Kelly

    I'll paste in some general responses to questions I have used over the last 2 months. The first paragrapgh below answers your question. Hope this helps.

    TLS 1.0

    First - as to why you received the email ... we are pulling a list every month of any orgs that are sending or receiving any email by TLS 1.0. Even if you have verified that your company's mail servers are using TLS 1.1 or higher, you could still show up on the list because one of your customers mail servers is still using TLS 1.0 and you sent mail to them or they sent mail to an email service that you own in Salesforce.

    Your main action should be to verify that your company'e mail servers are using TLS 1.1 or higher. If you have done that already - that's awesome. That is the main thing that is in your power to control. If you have not already done this verification, we have made 2 recent changes which will help you:

    1) For inbound mail to Salesforce, we now add a header that indicates the version of TLS used when the mail was sent to us - X-SFDC-TLS-VERSION. You can use the email capture facility as described in the original notifications to capture a mail sent from your service and verify the specific version of TLS used.

    2) For outbound mail, we recently put out a patch for the Spring 18 release that adds TLS version information to the Email Log access function available to Admins. Using that tool, you can pull information about mail that your organization has sent from Salesforce. It will show what version of TLS was used when delivering email.

    If your company's mail servers are good to go and the issue is with your customers that you are communicating with - you are correct in that it is a bit out of your control. For outbound email, you can use the admin logs to see who is using TLS 1.0 and notify them that they should look into upgrading if you wish to do so . For Inbound mail, the notifying action is really up to the sending mail servers.

    What happens after we disable TLS 1.0 for email in salesforce?

    For outbound mail: the email will still be delivered even if we cannot negotiate TLS - it will just be delivered unencrypted. The only exception to this is if you activate TLS Required. You can continue to use the Admin Email Log access function to see what version of TLS is being used or if its not being used. .

    For Inbound mail - the action taken when TLS cannot be negotiated is really up to the sending mail server. They should either send it unencrypted, or the message should be bounced back to the sender so they will get notification.

    At this point in time, we have seen the use of TLS 1.0 continue to slowly decline. In our most recent review across all mail sent to/from Salesforce, the amount of mail sent from our servers using TLS 1.0 was less than 2% and the amount of mail being delivered to us using TLS 1.0 was less than 2.5 %.

0/9000