THE APEX TIMES
Paubox Says Amazon SES Can Send “Require TLS” Emails in Plaintext, Even When TLS 1.2 Is Listed as Required
A healthcare email security vendor claims controlled tests found inconsistent encryption behavior in Amazon Simple Email Service (SES), raising questions for organizations preparing for tougher HIPAA enforcement.
Amazon Simple Email Service, or SES, has long been marketed as a way to send email over encrypted connections. But a new set of tests from Paubox, a provider focused on HIPAA-regulated email, argues that SES can still deliver sensitive health information in ways that fail to meet the security assurances customers may assume from Amazon’s documentation. Paubox said its researchers ran controlled experiments against SES in the second quarter of 2026 and used the recipient-side “Received” email headers to determine what encryption actually occurred.
In Paubox’s account, Amazon’s SES documentation says the service “requires TLS 1.2 and recommends TLS 1.3,” yet Paubox reported that SES delivered email using whatever TLS version the receiving server offered, including encryption protocols it said were considered retired by the Internet Engineering Task Force. Paubox also said the problem does not require an attacker, because it tied the failures to SES’s default “opportunistic TLS” behavior, where encryption is attempted but the message is sent even if a secure session cannot be established.
Paubox further claimed that SES’s “Require TLS” setting, which is designed to prevent delivery when TLS cannot be established, blocked only one of four failure modes Paubox says it tested. The company also said SES did not block tests involving invalid certificates, meaning an email could be delivered in encrypted form to servers that, in Paubox’s tests, could not prove their identity. Paubox’s chief executive, Hoala Greevy, was cited saying that “TLS being on is not the same as PHI being protected,” and that “Require TLS” does not enforce a minimum encryption version or certificate validation in the way many compliance teams expect.
Amazon SES’s own documentation describes a model that can help explain part of the dispute. For the SMTP interface, Amazon says clients must encrypt the connection using TLS, with TLS established either through STARTTLS or a TLS wrapper. More importantly for outbound delivery, Amazon says SES uses “opportunistic TLS” by default, which starts as plaintext and then upgrades to a TLS-encrypted session only if both sides support STARTTLS. Amazon also says that if SES cannot establish a secure connection, it sends the message unencrypted. Amazon notes that customers can change that default by using configuration sets and setting a TLS policy to “Require,” in which case SES will only deliver if it can establish a secure connection and will drop the message if it cannot.
The controversy lands as the United States moves toward stricter HIPAA cybersecurity expectations. On December 27, 2024, the Department of Health and Human Services Office for Civil Rights issued a notice of proposed rulemaking to strengthen the HIPAA Security Rule. In a published factsheet, HHS said the proposal would remove the distinction between “required” and “addressable” implementation specifications and would require encryption of electronic protected health information (ePHI) both at rest and in transit, with limited exceptions.
Paubox’s argument is that organizations may believe they are covered when they configure SES to “require TLS,” but that the actual protection level may vary depending on what the receiving server supports, and whether certificate checks are enforced. If that is accurate, the operational risk is not only confidentiality exposure, but also compliance uncertainty, because HIPAA security assessments often depend on evidence that required safeguards work as intended across real-world delivery paths.
Amazon did not respond in the reporting reviewed for this article, and Paubox did not provide full methodological details in the text available publicly here about which specific failure conditions were covered in all 14 tests, beyond describing the use of Received headers and categories of encryption and certificate behavior. As a result, the precise scope of what SES will do in every configuration, and whether differences depend on receiving-server behavior or SES API versus SMTP paths, remains something customers would likely need to verify directly in their own environments.
Why It Matters
- For healthcare and other regulated industries, email encryption often functions as a de facto control for protecting data in transit, and inconsistent enforcement can complicate compliance evidence.
- The dispute underscores a broader reality of SMTP delivery: encryption quality can depend on the receiving server’s configuration, and “encryption attempted” can differ from “encryption assured.”
- As proposed HIPAA changes move encryption from an “addressable” safeguard toward a required one, organizations may face more pressure to validate vendor behavior under realistic failure conditions, not just in ideal lab settings.
- If SES behavior varies based on receiving servers or certificate validation enforcement, security teams may need to test end-to-end delivery paths and not rely solely on configuration labels.
Sources
Key Facts
- Paubox said it ran 14 controlled tests against Amazon SES in Q2 2026 and evaluated results using recipient-side “Received” headers.
- Paubox claimed SES can deliver email in ways that include plaintext or encrypted delivery using TLS versions it described as retired, despite SES documentation stating TLS 1.2 is required.
- Paubox said SES’s “Require TLS” setting blocked only one of four failure modes it tested and that invalid-certificate scenarios were not blocked.
- Amazon’s SES documentation says it uses opportunistic TLS by default and will send messages unencrypted if a secure connection cannot be established.
- Amazon says customers can use SES configuration sets with a TLS policy of “Require,” causing SES to deliver only when it can establish a secure connection and to drop the message otherwise.
- HHS proposed in December 2024 to tighten HIPAA Security Rule cybersecurity requirements, including requiring encryption for ePHI in transit (and at rest) and removing “addressable” versus “required” distinctions.
Technology Related
Anthropic agrees to a $35 billion cloud computing deal tied to Nvidia-backed Lambda, report says
Anthropic PBC is reportedly moving to lock in large-scale compute capacity through a major multi-year arrangement with Lambda, a cloud provider backed by Nvidia. Terms and timelines were not fully disclosed in the report.
AMD has tended to fall in September, but market history is only part of the story
A review of the past decade points to a recurring pattern for AMD in September. The stock has declined in eight of the last 10 Septembers, though broader market seasonality appears to explain only some of the weakness.
Apple escalates claims against OpenAI, alleging evidence destruction in trade-secrets fight
In a new court filing, Apple accused OpenAI of actively destroying evidence tied to a trade-secrets dispute involving a former iPhone engineer. The company also pressed claims tied to alleged downloads of confidential information.
Duolingo shares jump after results point to steady user momentum, according to Yahoo Finance
A Yahoo Finance report highlighted that Duolingo’s second-quarter revenue rose 18% year over year, using the framing of a “Netflix-like comeback” after a period of volatility in the online learning category.
Netflix confirms production of Korean series “Materesa (WT),” led by “Queen of Tears” director and writers behind “The East Palace”
The streamer says its next Korean mystery drama, centered on a cold-blooded criminal psychologist who probes unsolved murders, is in production and has set a cast for “Materesa (WT).”
FTC and 22 States Sue Amazon, Alleging It Secretly Marked Up Ads Shown to Marketplace Sellers
The federal competition regulator and a coalition of states claim Amazon undercut third-party sellers on its platform by allegedly embedding surcharges into advertising terms.
FTC lawsuit by 22 states targets Amazon’s ad auction pricing, putting focus on high-margin advertising
The U.S. Federal Trade Commission says Amazon.com secretly inflated prices in its advertising auctions for more than seven years, while states joined the agency in the legal challenge.
Jensen Huang’s “Buy at a Discount” remark returns to focus as Nvidia shares rise and an AI basket gains
A CEO message to investors in June has been replayed after Nvidia’s stock moved higher over the following months, alongside gains in a broader AI peer group. Analysts caution that short-term trading often reflects many forces beyond a single CEO comment.
AMD says it is expanding its AI infrastructure footprint in Saudi Arabia
The chip designer announced a new platform initiative in Saudi Arabia, while investors appeared focused on how quickly the move could translate into additional AI-related revenue. AMD shares were little changed in Monday premarket trading.
Nvidia shares show a rare trading pattern, underscoring how investors are rethinking semiconductor correlations
A market-linked read of Nvidia’s stock behavior suggests its relationship with broader semiconductor moves has shifted, a change that can affect hedging, positioning, and how traders interpret near-term momentum.