Advanced email security configurations in Zoho Mail

Last updated: September 23, 2026

Zoho Mail is a secure email and collaboration platform that allows administrators to configure advanced security and encryption settings through the Zoho Mail Admin Console. 

Admins can configure the below settings from the Zoho Mail Admin Console to protect email communication at the brand, transport, and reporting level.

What is BIMI and how does it protect your brand in email?

Brand Indicators for Message Identification (BIMI) is an email authentication standard that displays your organization's verified logo next to your outgoing emails in the recipient's inbox. It adds a visible trust signal that helps recipients identify legitimate mail from your domain and reduces the risk of phishing impersonation. 

Admins can configure BIMI per domain from the Email Configuration section of the Zoho Mail Admin Console, after setting up DMARC enforcement and a Verified Mark Certificate (VMC).

Note:
Logo display depends on whether the recipient's email provider supports BIMI. Not all providers currently support it.


 To know more about step-by-step configuration, visit BIMI configurations in Zoho Mail.

What is MTA-STS and how does it secure email transmission?

MTA-STS (Mail Transfer Agent-Strict Transport Security) is an email security protocol that enforces TLS encryption for email connections between SMTP mail servers. 

When a sending server attempts to deliver email to your domain, MTA-STS instructs it to use an encrypted connection or block delivery entirely, preventing man-in-the-middle attacks, SMTP downgrade attacks, and email spoofing at the transport layer.

MTA-STS can be deployed in three modes: 

  • None (policy exists but does not enforce TLS)
  • Testing (policy is evaluated but email is not blocked)
  • Enforce (TLS is required; email is rejected if a secure connection cannot be established). 

Admins are recommended to start in Testing mode before switching to Enforce.

To know more details on step-by-step configuration, visit MTA-STS configuration in Zoho Mail.

What is TLS-RPT and why should admins configure it along with MTA-STS?

TLS-RPT (Transport Layer Security Reporting) sends both successful and failure reports to a configured email address covering TLS connection outcomes for all email delivery attempts. Failure reports include details such as certificate validation errors, handshake failures, and whether the failure resulted in a blocked or delivered message.

Configuring TLS-RPT alongside MTA-STS gives admins visibility into delivery issues before they affect users. This is especially useful when running in Testing mode to validate the MTA-STS policy before switching to Enforce. TLS-RPT is configured from the Email Configuration section in the Zoho Mail Admin Console.

Learn how to configure TLS-RPT in Zoho Mail Admin Console.

PREVIOUS

UP NEXT