Business Wire
BusinessTelecom comparison turns on profitability pace versus leverage: AT&T’s margin jump, Verizon’s debt loadThe Apex TimesBusinessAnthropic agrees to a $35 billion cloud computing deal tied to Nvidia-backed Lambda, report saysThe Apex TimesBusinessAMD has tended to fall in September, but market history is only part of the storyThe Apex TimesBusinessApple escalates claims against OpenAI, alleging evidence destruction in trade-secrets fightThe Apex TimesBusinessDuolingo shares jump after results point to steady user momentum, according to Yahoo FinanceThe Apex TimesBusinessNetflix confirms production of Korean series “Materesa (WT),” led by “Queen of Tears” director and writers behind “The East Palace”The Apex TimesBusinessFTC and 22 States Sue Amazon, Alleging It Secretly Marked Up Ads Shown to Marketplace SellersThe Apex TimesBusinessDeere shares gained as market focused on a jump in profitsThe Apex TimesBusinessBaird lifts Deere to Outperform, citing potential agricultural recovery and raises target to $800The Apex TimesBusinessVenezuela’s energy reopening talks could create upside for Chevron and GE Vernova, but agreements still face major hurdlesThe Apex TimesBusinessTrump Says ExxonMobil Is Preparing to Re-enter Venezuela as Investment Outlook ShiftsThe Apex TimesBusinessFTC lawsuit by 22 states targets Amazon’s ad auction pricing, putting focus on high-margin advertisingThe Apex TimesBusinessTelecom comparison turns on profitability pace versus leverage: AT&T’s margin jump, Verizon’s debt loadThe Apex TimesBusinessAnthropic agrees to a $35 billion cloud computing deal tied to Nvidia-backed Lambda, report saysThe Apex TimesBusinessAMD has tended to fall in September, but market history is only part of the storyThe Apex TimesBusinessApple escalates claims against OpenAI, alleging evidence destruction in trade-secrets fightThe Apex TimesBusinessDuolingo shares jump after results point to steady user momentum, according to Yahoo FinanceThe Apex TimesBusinessNetflix confirms production of Korean series “Materesa (WT),” led by “Queen of Tears” director and writers behind “The East Palace”The Apex TimesBusinessFTC and 22 States Sue Amazon, Alleging It Secretly Marked Up Ads Shown to Marketplace SellersThe Apex TimesBusinessDeere shares gained as market focused on a jump in profitsThe Apex TimesBusinessBaird lifts Deere to Outperform, citing potential agricultural recovery and raises target to $800The Apex TimesBusinessVenezuela’s energy reopening talks could create upside for Chevron and GE Vernova, but agreements still face major hurdlesThe Apex TimesBusinessTrump Says ExxonMobil Is Preparing to Re-enter Venezuela as Investment Outlook ShiftsThe Apex TimesBusinessFTC lawsuit by 22 states targets Amazon’s ad auction pricing, putting focus on high-margin advertisingThe Apex TimesBusinessTelecom comparison turns on profitability pace versus leverage: AT&T’s margin jump, Verizon’s debt loadThe Apex TimesBusinessAnthropic agrees to a $35 billion cloud computing deal tied to Nvidia-backed Lambda, report saysThe Apex TimesBusinessAMD has tended to fall in September, but market history is only part of the storyThe Apex TimesBusinessApple escalates claims against OpenAI, alleging evidence destruction in trade-secrets fightThe Apex TimesBusinessDuolingo shares jump after results point to steady user momentum, according to Yahoo FinanceThe Apex TimesBusinessNetflix confirms production of Korean series “Materesa (WT),” led by “Queen of Tears” director and writers behind “The East Palace”The Apex TimesBusinessFTC and 22 States Sue Amazon, Alleging It Secretly Marked Up Ads Shown to Marketplace SellersThe Apex TimesBusinessDeere shares gained as market focused on a jump in profitsThe Apex TimesBusinessBaird lifts Deere to Outperform, citing potential agricultural recovery and raises target to $800The Apex TimesBusinessVenezuela’s energy reopening talks could create upside for Chevron and GE Vernova, but agreements still face major hurdlesThe Apex TimesBusinessTrump Says ExxonMobil Is Preparing to Re-enter Venezuela as Investment Outlook ShiftsThe Apex TimesBusinessFTC lawsuit by 22 states targets Amazon’s ad auction pricing, putting focus on high-margin advertisingThe Apex TimesBusinessTelecom comparison turns on profitability pace versus leverage: AT&T’s margin jump, Verizon’s debt loadThe Apex TimesBusinessAnthropic agrees to a $35 billion cloud computing deal tied to Nvidia-backed Lambda, report saysThe Apex TimesBusinessAMD has tended to fall in September, but market history is only part of the storyThe Apex TimesBusinessApple escalates claims against OpenAI, alleging evidence destruction in trade-secrets fightThe Apex TimesBusinessDuolingo shares jump after results point to steady user momentum, according to Yahoo FinanceThe Apex TimesBusinessNetflix confirms production of Korean series “Materesa (WT),” led by “Queen of Tears” director and writers behind “The East Palace”The Apex TimesBusinessFTC and 22 States Sue Amazon, Alleging It Secretly Marked Up Ads Shown to Marketplace SellersThe Apex TimesBusinessDeere shares gained as market focused on a jump in profitsThe Apex TimesBusinessBaird lifts Deere to Outperform, citing potential agricultural recovery and raises target to $800The Apex TimesBusinessVenezuela’s energy reopening talks could create upside for Chevron and GE Vernova, but agreements still face major hurdlesThe Apex TimesBusinessTrump Says ExxonMobil Is Preparing to Re-enter Venezuela as Investment Outlook ShiftsThe Apex TimesBusinessFTC lawsuit by 22 states targets Amazon’s ad auction pricing, putting focus on high-margin advertisingThe Apex Times
Back to front
Paubox Says Amazon SES Can Send “Require TLS” Emails in Plaintext, Even When TLS 1.2 Is Listed as Required
The Apex Times

THE APEX TIMES

Business/The Apex Times/Jun 8, 2:00 PM EDT

Paubox Says Amazon SES Can Send “Require TLS” Emails in Plaintext, Even When TLS 1.2 Is Listed as Required

A healthcare email security vendor claims controlled tests found inconsistent encryption behavior in Amazon Simple Email Service (SES), raising questions for organizations preparing for tougher HIPAA enforcement.

Amazon Simple Email Service, or SES, has long been marketed as a way to send email over encrypted connections. But a new set of tests from Paubox, a provider focused on HIPAA-regulated email, argues that SES can still deliver sensitive health information in ways that fail to meet the security assurances customers may assume from Amazon’s documentation. Paubox said its researchers ran controlled experiments against SES in the second quarter of 2026 and used the recipient-side “Received” email headers to determine what encryption actually occurred.

In Paubox’s account, Amazon’s SES documentation says the service “requires TLS 1.2 and recommends TLS 1.3,” yet Paubox reported that SES delivered email using whatever TLS version the receiving server offered, including encryption protocols it said were considered retired by the Internet Engineering Task Force. Paubox also said the problem does not require an attacker, because it tied the failures to SES’s default “opportunistic TLS” behavior, where encryption is attempted but the message is sent even if a secure session cannot be established.

Paubox further claimed that SES’s “Require TLS” setting, which is designed to prevent delivery when TLS cannot be established, blocked only one of four failure modes Paubox says it tested. The company also said SES did not block tests involving invalid certificates, meaning an email could be delivered in encrypted form to servers that, in Paubox’s tests, could not prove their identity. Paubox’s chief executive, Hoala Greevy, was cited saying that “TLS being on is not the same as PHI being protected,” and that “Require TLS” does not enforce a minimum encryption version or certificate validation in the way many compliance teams expect.

Amazon SES’s own documentation describes a model that can help explain part of the dispute. For the SMTP interface, Amazon says clients must encrypt the connection using TLS, with TLS established either through STARTTLS or a TLS wrapper. More importantly for outbound delivery, Amazon says SES uses “opportunistic TLS” by default, which starts as plaintext and then upgrades to a TLS-encrypted session only if both sides support STARTTLS. Amazon also says that if SES cannot establish a secure connection, it sends the message unencrypted. Amazon notes that customers can change that default by using configuration sets and setting a TLS policy to “Require,” in which case SES will only deliver if it can establish a secure connection and will drop the message if it cannot.

The controversy lands as the United States moves toward stricter HIPAA cybersecurity expectations. On December 27, 2024, the Department of Health and Human Services Office for Civil Rights issued a notice of proposed rulemaking to strengthen the HIPAA Security Rule. In a published factsheet, HHS said the proposal would remove the distinction between “required” and “addressable” implementation specifications and would require encryption of electronic protected health information (ePHI) both at rest and in transit, with limited exceptions.

Paubox’s argument is that organizations may believe they are covered when they configure SES to “require TLS,” but that the actual protection level may vary depending on what the receiving server supports, and whether certificate checks are enforced. If that is accurate, the operational risk is not only confidentiality exposure, but also compliance uncertainty, because HIPAA security assessments often depend on evidence that required safeguards work as intended across real-world delivery paths.

Amazon did not respond in the reporting reviewed for this article, and Paubox did not provide full methodological details in the text available publicly here about which specific failure conditions were covered in all 14 tests, beyond describing the use of Received headers and categories of encryption and certificate behavior. As a result, the precise scope of what SES will do in every configuration, and whether differences depend on receiving-server behavior or SES API versus SMTP paths, remains something customers would likely need to verify directly in their own environments.

Why It Matters

  • For healthcare and other regulated industries, email encryption often functions as a de facto control for protecting data in transit, and inconsistent enforcement can complicate compliance evidence.
  • The dispute underscores a broader reality of SMTP delivery: encryption quality can depend on the receiving server’s configuration, and “encryption attempted” can differ from “encryption assured.”
  • As proposed HIPAA changes move encryption from an “addressable” safeguard toward a required one, organizations may face more pressure to validate vendor behavior under realistic failure conditions, not just in ideal lab settings.
  • If SES behavior varies based on receiving servers or certificate validation enforcement, security teams may need to test end-to-end delivery paths and not rely solely on configuration labels.

Sources

Key Facts

  • Paubox said it ran 14 controlled tests against Amazon SES in Q2 2026 and evaluated results using recipient-side “Received” headers.
  • Paubox claimed SES can deliver email in ways that include plaintext or encrypted delivery using TLS versions it described as retired, despite SES documentation stating TLS 1.2 is required.
  • Paubox said SES’s “Require TLS” setting blocked only one of four failure modes it tested and that invalid-certificate scenarios were not blocked.
  • Amazon’s SES documentation says it uses opportunistic TLS by default and will send messages unencrypted if a secure connection cannot be established.
  • Amazon says customers can use SES configuration sets with a TLS policy of “Require,” causing SES to deliver only when it can establish a secure connection and to drop the message otherwise.
  • HHS proposed in December 2024 to tighten HIPAA Security Rule cybersecurity requirements, including requiring encryption for ePHI in transit (and at rest) and removing “addressable” versus “required” distinctions.

Technology Related

Paubox Says Amazon SES Can Send “Require TLS” Emails in Plaintext, Even When TLS 1.2 Is Listed as Required | The Apex Times