Conversation

This is what we use for the GrapheneOS web servers: github.com/GrapheneOS/gra If you don't care about supporting legacy clients including various bots, disable TLS 1.2. TLS 1.3 only has ECDHE. For email it's a bit different due to servers without DANE falling back to plain text.
1
1
Our solution to that email server issue is disabling support for unencrypted connections. That's obviously not something most people would accept since they would be concerned about missing emails. For us, we're more than happy to reject mail from broken / insecure mail servers.
3