If you use external, third-party email which is outside of your firewall and you have no control over the email domain, is it still beneficial to TLS decrypt IMAPS, POP3S, SMTPS traffic and thus have it inspected? Actually, as I write this I'm not sure what service actually would inspect it. (IDP, Malware, ?)
Just to be clear, behind the XGS (18.5) are users who reach outside of the firewall to third-party email services to send and receive email. It's apparently not that useful to subscribe to the Email subscription in that case. So then there's the choice of figuring the large third parties do spam and spoofing checking and potentially malware scanning -- haven't seen any evidence of that, but they might -- and leaving the up/down mail traffic encrypted and relying on the third parties and the email client to keep things clean.
Or you could add endpoint software so you have multiple things checking for evil email. And/or you could TLS decrypt the IMAPS/SMTPS traffic and maybe some other kinds of things are done in the XGS (again, without Email subscription so you can't turn on IMAPS scanning, etc) that might be helpful.
Thoughts? If I turn on TLS decryption on IMAPS/SMTPS traffic and don't have an Email subscription, is anything useful happening? Or should I just not decrypt that traffic and save myself potential breakages and errors?
This thread was automatically locked due to age.