TLS connection failed
The SMTP encrypted connection could not be established.
What to do now
- Check whether the server supports STARTTLS.
- Check that the port matches STARTTLS or implicit TLS.
- Inspect TLS settings, the certificate chain and negotiation results.
Representative reply
TLS handshake failure
Retry decision
Retry after correcting TLS settings and certificate issues.
Why it happens
TLS versions, ciphers, certificates or port security mode may be incompatible.
Typical stage
TLS / STARTTLS
- CONNECT
- TLS / STARTTLS
- EHLO
- MAIL FROM
- RCPT TO
- DATA
- DELIVERY
Stages vary by server. Confirm the actual stage from the complete reply and session logs.
What is SMTP Reply Code?Open only the explanations you need
Three-digit server reply: 4xx is transient, 5xx permanent. Read the complete text to investigate the cause.
What is Enhanced Status Code?Open only the explanations you need
An extended status such as 5.1.1. Server wording and usage may vary.
What is STARTTLS / TLS?Open only the explanations you need
STARTTLS upgrades an existing connection. Implicit TLS encrypts from connection establishment.
Check directly
- Check whether the server supports STARTTLS.
- Check that the port matches STARTTLS or implicit TLS.
- Inspect TLS settings, the certificate chain and negotiation results.
If you operate or diagnose the mail server, the tools below can help with these checks.
openssl s_client -starttls smtp -connect mx.example.com:25 -crlf
Cautions
Observed DSNs do not map one-to-one to causes. The stage shown is typical; confirm it with the full reply and actual logs.
Similar reply wording and observed status codes
handshake failure
Observed DSNs: 4.7.5