What security can we implement in PHPmailer to make it a more secure app for Gmail? https://support.google.com/accounts/answer/6010255 I am using PHPmailer to send emails via Gmail. PS: I don't want to enable "access for less secure apps" here: https://www.google.com/settings/security/lesssecureapps, I want to make the app more secure.
相关问题
- Django & Amazon SES SMTP. Cannot send email
- “Zero out” sensitive String data in Swift
- High cost encryption but less cost decryption
- PHP trying to send mail securely - cannot find the
- How to restrict VOB read access in ClearCase (Wind
相关文章
- c#发送邮件,附件损坏
- Warning : HTML 1300 Navigation occured?
- Security concerns about CORS
- How do I prevent SQL injection with ColdFusion
- com.sun.mail.smtp.SMTPSenderFailedException: 550 5
- Debug HTML Email in Gmail App
- Sending email using php, gmail, and swiftmailer ca
- LINQ to Entities and SQL Injection
Gmail has started imposing a new authentication mechanism that substitutes SMTP athentication for OAuth2-based authorisation. The docs on their changes can be found here.
This doens't really improve security much because ultimately you still need to submit your username and password over SSL at some point (the very mechanism that google deems insecure) to authenticate to get an OAuth token, which is exactly as secure as existing SMTP auth systems.
As yet, PHPMailer does not support this new mechanism - PRs welcome! You will need an OAuth2 class, such as this one, and perhaps make use of this code example.
In the mean time, you do have to "enable access for less secure apps", and you should set
SMTPSecure = 'tls'
andPort = 587
and use normal auth to connect using PHPMailer.Update
PHPMailer supports Gmail's XOAUTH2 authentication as of version 5.2.11. See this guide. It's being expanded in version 6.0 to support other services too.