@misc{rfc9787, series = {Request for Comments}, number = 9787, howpublished = {RFC 9787}, publisher = {RFC Editor}, doi = {10.17487/RFC9787}, url = {https://www.rfc-editor.org/info/rfc9787}, author = {Daniel Kahn Gillmor and Bernie Hoeneisen and Alexey Melnikov}, title = {{Guidance on End-to-End Email Security}}, pagetotal = 53, year = 2025, month = aug, abstract = {End-to-end cryptographic protections for email messages can provide useful security. However, the standards for providing cryptographic protection are extremely flexible. That flexibility can trap users and cause surprising failures. This document offers guidance for Mail User Agent (MUA) implementers to help mitigate those risks and to make end-to-end email simple and secure for the end user. It provides a useful set of vocabulary as well as recommendations to avoid common failures. It also identifies a number of currently unsolved usability and interoperability problems.}, }