Yoonadev

TLS connection failed

The SMTP encrypted connection could not be established.

What to do now

  1. Check whether the server supports STARTTLS.
  2. Check that the port matches STARTTLS or implicit TLS.
  3. Inspect TLS settings, the certificate chain and negotiation results.

Representative reply

TLS handshake failure

Retry decision

Retry after correcting TLS settings and certificate issues.

Why it happens

TLS versions, ciphers, certificates or port security mode may be incompatible.

Typical stage

TLS / STARTTLS

  1. CONNECT
  2. TLS / STARTTLS
  3. EHLO
  4. MAIL FROM
  5. RCPT TO
  6. DATA
  7. DELIVERY

Stages vary by server. Confirm the actual stage from the complete reply and session logs.

What is SMTP Reply Code?Open only the explanations you need

Three-digit server reply: 4xx is transient, 5xx permanent. Read the complete text to investigate the cause.

What is Enhanced Status Code?Open only the explanations you need

An extended status such as 5.1.1. Server wording and usage may vary.

What is STARTTLS / TLS?Open only the explanations you need

STARTTLS upgrades an existing connection. Implicit TLS encrypts from connection establishment.

Check directly

  1. Check whether the server supports STARTTLS.
  2. Check that the port matches STARTTLS or implicit TLS.
  3. Inspect TLS settings, the certificate chain and negotiation results.

If you operate or diagnose the mail server, the tools below can help with these checks.

openssl s_client -starttls smtp -connect mx.example.com:25 -crlf

Cautions

Observed DSNs do not map one-to-one to causes. The stage shown is typical; confirm it with the full reply and actual logs.

Similar reply wording and observed status codes
  • handshake failure

Observed DSNs: 4.7.5

Related errors

Analyze another SMTP error →

Back to SMTP Error Dictionary

Find a tool

↑ ↓ to select · Enter to open · Esc to close