Skip to main content
  1. Home
  2. Computing
  3. Mobile
  4. Web
  5. News

Google, Microsoft, and Yahoo want to make email immune to man-in-the-middle attacks

Add as a preferred source on Google

In the era of Apple vs. FBI, and large scale hacks on a regular basis, most of us are slowly becoming aware that our data isn’t as protected as it could be. Google, Amazon, Facebook, Microsoft, and a number of other tech giants, however, are banding together to improve the security of email traffic around the Internet.

Software engineers from these companies are working together to create a new system called SMTP Strict Transport Security, which is a mechanism that essentially allows email providers to define new rules for creating encrypted email connections.

Recommended Videos

The new technology is necessary, especially because of the fact that security standards for emails have largely remained the same for years, leaving most emails un-encrypted and open to “man-in-the-middle” hacks, which intercept the email, or change its contents, en route to its destination. When email was first introduced, it used the Simple Mail Transfer Protocol, or SMPT, which did not have any encryption built in at all. Because of this, in 2002 an extension called STARTTLS was added to offer TLS, or Transport Layer Security, encryption with SMTP connections.

According to research by the firms behind the new protocol, one of the main problems with this standard, apart from the fact that it took a long time to be widely adopted, is the fact that if anything goes wrong with the sending of the email along the way, it will be sent unencrypted by default. Not only that, but STARTTLS also uses what’s called opportunistic encryption, which means that it doesn’t validate a server’s digital certificate, and if it cannot verify a server’s identity, it assumes that sending the email is still better than nothing.

This leads to the man-in-the-middle vulnerability, where a hacker can be put in position to intercept traffic by presenting any certificate, even if it is self-signed. That lets the hacker decrypt the email, and thus defeating the purpose of having encrypted emails in the first place.

SMTP Strict Transport Security seeks to solve this problem. The new protocol is designed to prevent an email from being delivered if the message cannot be delivered securely. It will also check to make sure the email’s certificate is a valid one, and in the event of a non-valid certificate, the email won’t be delivered, and the sender will be told why.

The proposal for the system has been sent to the Internet Engineering Task Force, and can be found in full here. If the proposal does succeed, we could soon be sending and receiving much more secure emails.

Christian de Looper
Christian de Looper is a long-time freelance writer who has covered every facet of the consumer tech and electric vehicle…
Google just gave Workspace a 24/7 AI agent that sends emails and books meetings while you sleep
Google announcing five Workspace features at once is either confidence or chaos, but Gemini Spark acting on your behalf while you sleep is the one that actually changes what a productivity suite is supposed to do.
Google AI Inbox for Gmail users.

At the I/O 2026, Google announced several AI-powered updates for its Workspace apps. The main highlight of the announcement is Gemini Spark, a 24/7 personal AI agent that doesn’t just answer questions but takes actions on your behalf. 

It can send emails, add calendar events, and complete tasks across Workspace apps. And before you even ask, it asks before doing a high-stakes task, and you can choose whether you want to enable it or not. It's coming soon in preview for Workspace business customers in the Gemini app.

Read more
Gemini can now make videos, brief your morning, and do digital chores while you sleep
Gemini is now an AI intern that never logs off
Google Gemini App gets a major update

Google is giving the Gemini app a massive update, bringing a bunch of nifty changes. The chatbot phase is fading, and the company now wants Gemini to become something closer to a full-time digital assistant.

During Google I/O 2026, the company announced a redesigned Gemini app along with a new model, proactive daily summaries, video tools, and a 24/7 agent called Gemini Spark. Google claims that Gemini has now reached more than 900 million monthly users across 230 countries and more than 70 languages, up from 400 million last year.

Read more
Google Search is getting AI agents that will monitor the web for you
Set up an agent once, and Search will notify you when it finds what you're looking for.
Google Search information agents featured

Google used its I/O 2026 keynote to announce a major overhaul of Search, introducing AI agents, a redesigned search box, and agentic coding capabilities that can generate custom apps and dashboards on the fly.

A new search box

Read more