I use the Pro version and I am very happy with Aquamail.
However, since Cyanogenmod adjusted the default cipher list and preferred SSL/TLS protocol version list (see review.cyanogenmod.org/#/c/51771/), I cannot connect (securely) to my (outdated) E-Mail server of my university. When trying a TLSv1.2 or TLSv1.1, the server cancels the connection attempt with a "Handshake Failure" error, because it only supports TLS1.0 (WTF?!).
I would therefore like to see an option (in the manual account setup) that allows to force the use of SSLv3, TLSv1.0, TLSv1.1 or TLSv1.2.
My vision is something like this: When SSL (strict check or accept any) is selected, a checkbox appears or gets available that says "Force a specific SSL/TLS version". When this is ticked, a dropdown menu becomes available where one can choose the desired encryption protocol version manually.
This would not only help with outdated servers, it would also allow people to force the use of a newer and stronger protocol version, given that the server supports it, although the server would like to use an older one. In short: Help mitigate bidding down attacks.
On a side note: It should say "SSL/TLS", not just "SSL", because "SSL" suggests that only SSLv3 is used.
What do you think?
Best,
schlimmchen