DirectAdmin uses the intermediate config from Mozilla since a few years if a remember correctly and that uses TLS 1.2 and up also for Exim. There are still many Exim servers with old configs and for that reason I changed that to use TLS 1.0 and up only for Exim with the correct ciphers. I'm just curious what Exim config you use and if it's "safe" these days to disable TLS 1.0 and 1.1 for Exim and if you encounter delivery issues. Thinking of doing some tests to change this to TLS 1.2.
See this explanation from the Internet.nl test (translated from Dutch):
See this explanation from the Internet.nl test (translated from Dutch):
Note that quite a few mail servers only support older TLS versions. If the sending and receiving mail servers do not both support the same TLS version, they will typically fall back to unencrypted transport. For this reason, it may be advisable to continue to support the TLS versions with 'phasing out' status for the time being. Based on log data, make a well-considered choice about disabling these 'to be phased out' TLS versions.
See 'ICT security guidelines for Transport Layer Security (TLS) v2.1' from NCSC, guideline B1-1 and table 1