Skip to content

[API Proposal]: SmtpClient.SslOptions #120965

Description

@rzikm

Background and motivation

SmtpClient can be configured to use TLS via SmtpClient.EnableSsl property, but at this time, there is no way to configure the actual TLS connection parameters (client certs, remote certificate validation, etc). This is one of the last areas that is still affected by ServicePointManager (for SslProtocols and cert validation).

API Proposal

namespace System.Net.Mail;

public partial class SmtpClient
{
    // lazily initialized on get;, has no effect if EnableSsl == false
+   public SslClientAuthenticationOptions SslOptions { get; set; }

    // existing member
+   [Obsolete("Use SslOptions.ClientCertificates instead")]
    public X509CertificatesCollection ClientCertificates { get; } // => SslOptions.ClientCertificates
}

API Usage

SmtpClient client = new(...) {
    SslOptions = {
        ClientCertificates = new () { myClientCertificate },
        RemoteCertificateValidationCallback = delegate { return true; }, // imagine complicated validation logic here,
        
        TargetHost = "smtp.somehost.com" // if not set, defaults to SmtpClient.Host,
        
        // there is no smtp in IANA registry, so ALPN is not used with SMTP, but we would probably respect whatever user
        // decided they want to send
        // ApplicationProtocols = [ new SslApplicationProtocol("whatever-i-want") ]

        // other members omited for brevity
    }
}

Alternative Designs

No response

Risks

No response

Activity

  1. added
    api-suggestionEarly API idea and discussion, it is NOT ready for implementation
    on Oct 22, 2025
  2. dotnet-policy-service commented on Oct 22, 2025

    @dotnet-policy-service
    Contributor

    Tagging subscribers to this area: @dotnet/ncl
    See info in area-owners.md if you want to be subscribed.

  3. removed
    untriagedNew issue has not been triaged by the area owner
    on Oct 22, 2025
  4. added this to the Future milestone on Oct 22, 2025
  5. added
    api-ready-for-reviewAPI is ready for review, it is NOT ready for implementation
    and removed
    api-suggestionEarly API idea and discussion, it is NOT ready for implementation
    on Aug 26, 2026
  6. added theissue type on Aug 26, 2026
  7. bartonjs commented on Sep 29, 2026

    @bartonjs
    Member

    Video

    • It doesn't seem like obsoleting the existing property provides a lot of value, there's no impact on existing callers.
      • We couldn't strongly decide on EB-Never either
    namespace System.Net.Mail;
    
    public partial class SmtpClient
    {
        public SslClientAuthenticationOptions SslOptions { get; set; }
    
        // existing member defers to new one
        //public X509CertificatesCollection ClientCertificates { get; } // => SslOptions.ClientCertificates
    }
  8. added
    api-approvedAPI was approved in API review, it can be implemented
    and removed
    api-ready-for-reviewAPI is ready for review, it is NOT ready for implementation
    on Sep 29, 2026
  9. self-assigned this
    on Sep 30, 2026
  10. added a commit that references this issue on Oct 7, 2026
    122c28f
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions