Troubleshooting
Why do I get TLS errors when connecting to SMTP?
Fix SSL and TLS handshake errors with smtp.emailit.com, such as "wrong version number", certificate name mismatches and STARTTLS failures.
This article covers errors that happen while your client and the Emailit SMTP relay set up encryption. They almost always come from a mismatch between the port and the TLS mode in your client.
Symptoms
SSL routines:ssl3_get_record:wrong version numberorERR_SSL_WRONG_VERSION_NUMBERHostname/IP does not match certificate's altnamesorcertificate verify failedSTARTTLS failed,Greeting never receivedor the connection hangs after connectunsupported protocolorno protocols available
Cause
Emailit uses two TLS modes, and each port expects one of them:
| Port | Mode | Typical client setting |
|---|---|---|
| 587, 2525, 2587, 25 | STARTTLS: the session starts in plain text and upgrades | Nodemailer secure: false, PHPMailer ENCRYPTION_STARTTLS, “TLS” in most UIs |
| 465 | Implicit TLS: encrypted from the first byte | Nodemailer secure: true, PHPMailer ENCRYPTION_SMTPS, “SSL” in most UIs |
The common causes are:
- Implicit TLS on a STARTTLS port, for example
secure: truewith port 587. The client expects a TLS handshake but receives a plain-text greeting, which produces “wrong version number”. - STARTTLS on port 465. The client waits for a greeting the server never sends in clear text, so the connection hangs.
- Connecting by IP address or through your own CNAME. The certificate is issued for
smtp.emailit.com, so any other host name fails verification. - An old TLS stack. The relay negotiates TLS 1.2 or TLS 1.3. Clients limited to TLS 1.0 or 1.1, or with an outdated CA bundle, can’t complete the handshake.
- Traffic inspection. Some antivirus tools and corporate proxies intercept SMTP and present their own certificate.
Fix
-
Match the port to the mode. Use port
587with STARTTLS, or port465with implicit TLS. Don’t mix them.const transporter = nodemailer.createTransport({ host: 'smtp.emailit.com', port: 587, secure: false, // STARTTLS on 587; set true only for port 465 requireTLS: true, // refuse to send if the upgrade fails auth: { user: 'emailit', pass: process.env.EMAILIT_API_KEY }, }); -
Use the exact host name. Set the host to
smtp.emailit.com. Don’t use an IP address or an alias. -
Require encryption in your client. STARTTLS is offered on every plain-text port, but the relay doesn’t force it. Turn on your client’s “require TLS” option so credentials are never sent unencrypted.
-
Test the handshake from the sending machine.
openssl s_client -starttls smtp -connect smtp.emailit.com:587 -servername smtp.emailit.com openssl s_client -connect smtp.emailit.com:465 -servername smtp.emailit.comA healthy result shows
subject=CN=smtp.emailit.comandVerify return code: 0 (ok). A different subject means something on your network is intercepting the connection. -
Update old runtimes. Upgrade the language runtime or OpenSSL and the system CA certificates if your client can’t negotiate TLS 1.2.
If the handshake succeeds but login fails, see Why does SMTP return 535 Authentication failed?. If you can’t connect at all, see Why does my SMTP connection time out?.
Still stuck?
Contact support or ask in Discord. Include the port, your client library and version, and the output of the openssl s_client command.