# Why do I get TLS errors when connecting to SMTP?

> Fix SSL and TLS handshake errors with smtp.emailit.com, such as "wrong version number", certificate name mismatches and STARTTLS failures.

This article covers errors that happen while your client and the Emailit SMTP relay set up encryption. They almost always come from a mismatch between the port and the TLS mode in your client.

## Symptoms

- `SSL routines:ssl3_get_record:wrong version number` or `ERR_SSL_WRONG_VERSION_NUMBER`
- `Hostname/IP does not match certificate's altnames` or `certificate verify failed`
- `STARTTLS failed`, `Greeting never received` or the connection hangs after connect
- `unsupported protocol` or `no protocols available`

## Cause

Emailit uses two TLS modes, and each port expects one of them:

| Port | Mode | Typical client setting |
| --- | --- | --- |
| 587, 2525, 2587, 25 | **STARTTLS**: the session starts in plain text and upgrades | Nodemailer `secure: false`, PHPMailer `ENCRYPTION_STARTTLS`, "TLS" in most UIs |
| 465 | **Implicit TLS**: encrypted from the first byte | Nodemailer `secure: true`, PHPMailer `ENCRYPTION_SMTPS`, "SSL" in most UIs |

The common causes are:

- **Implicit TLS on a STARTTLS port**, for example `secure: true` with port 587. The client expects a TLS handshake but receives a plain-text greeting, which produces "wrong version number".
- **STARTTLS on port 465.** The client waits for a greeting the server never sends in clear text, so the connection hangs.
- **Connecting by IP address or through your own CNAME.** The certificate is issued for `smtp.emailit.com`, so any other host name fails verification.
- **An old TLS stack.** The relay negotiates TLS 1.2 or TLS 1.3. Clients limited to TLS 1.0 or 1.1, or with an outdated CA bundle, can't complete the handshake.
- **Traffic inspection.** Some antivirus tools and corporate proxies intercept SMTP and present their own certificate.

## Fix

1. **Match the port to the mode.** Use port `587` with STARTTLS, or port `465` with implicit TLS. Don't mix them.

```javascript title="mailer.js"
const transporter = nodemailer.createTransport({
  host: 'smtp.emailit.com',
  port: 587,
  secure: false,     // STARTTLS on 587; set true only for port 465
  requireTLS: true,  // refuse to send if the upgrade fails
  auth: { user: 'emailit', pass: process.env.EMAILIT_API_KEY },
});
```

2. **Use the exact host name.** Set the host to `smtp.emailit.com`. Don't use an IP address or an alias.

3. **Require encryption in your client.** STARTTLS is offered on every plain-text port, but the relay doesn't force it. Turn on your client's "require TLS" option so credentials are never sent unencrypted.

4. **Test the handshake from the sending machine.**

```bash
openssl s_client -starttls smtp -connect smtp.emailit.com:587 -servername smtp.emailit.com
openssl s_client -connect smtp.emailit.com:465 -servername smtp.emailit.com
```

   A healthy result shows `subject=CN=smtp.emailit.com` and `Verify return code: 0 (ok)`. A different subject means something on your network is intercepting the connection.

5. **Update old runtimes.** Upgrade the language runtime or OpenSSL and the system CA certificates if your client can't negotiate TLS 1.2.

If the handshake succeeds but login fails, see [Why does SMTP return 535 Authentication failed?](/docs/kb/smtp-535-authentication-failed/). If you can't connect at all, see [Why does my SMTP connection time out?](/docs/kb/smtp-connection-timeout-port-25/).

## Still stuck?

[Contact support](/contact/) or ask in [Discord](https://discord.emailit.com). Include the port, your client library and version, and the output of the `openssl s_client` command.

---
Source: https://emailit.com/docs/kb/smtp-tls-errors/
