Welcome to the #dominoforever Product Ideas Forum! The place where you can submit product ideas and enhancement request. We encourage you to participate by voting on, commenting on, and creating new ideas. All new ideas will be evaluated by HCL Product Management & Engineering teams, and the next steps will be communicated. While not all submitted ideas will be executed upon, community feedback will play a key role in influencing which ideas are and when they will be implemented.
Are you sure the certificate is checked? I never ran into any issue with a remote site not having a valid cert.
I would want to ask for the opposite functionality:
Have a way to enforce certificate validation for specified recipient domains to allow qualified STARTTLS.
Or the other way round to always validate and have a way to configure domains to skip this validation.
We need more control in this area for incoming and more important outgoing messages.
What prevents MTM attack in this case?