Skip to content
Docs

Troubleshooting

Why do I get TLS errors when connecting to SMTP?

Fix SSL and TLS handshake errors with smtp.emailit.com, such as "wrong version number", certificate name mismatches and STARTTLS failures.

Updated Oct 1, 2026

This article covers errors that happen while your client and the Emailit SMTP relay set up encryption. They almost always come from a mismatch between the port and the TLS mode in your client.

Symptoms

  • SSL routines:ssl3_get_record:wrong version number or ERR_SSL_WRONG_VERSION_NUMBER
  • Hostname/IP does not match certificate's altnames or certificate verify failed
  • STARTTLS failed, Greeting never received or the connection hangs after connect
  • unsupported protocol or no protocols available

Cause

Emailit uses two TLS modes, and each port expects one of them:

Port Mode Typical client setting
587, 2525, 2587, 25 STARTTLS: the session starts in plain text and upgrades Nodemailer secure: false, PHPMailer ENCRYPTION_STARTTLS, “TLS” in most UIs
465 Implicit TLS: encrypted from the first byte Nodemailer secure: true, PHPMailer ENCRYPTION_SMTPS, “SSL” in most UIs

The common causes are:

  • Implicit TLS on a STARTTLS port, for example secure: true with port 587. The client expects a TLS handshake but receives a plain-text greeting, which produces “wrong version number”.
  • STARTTLS on port 465. The client waits for a greeting the server never sends in clear text, so the connection hangs.
  • Connecting by IP address or through your own CNAME. The certificate is issued for smtp.emailit.com, so any other host name fails verification.
  • An old TLS stack. The relay negotiates TLS 1.2 or TLS 1.3. Clients limited to TLS 1.0 or 1.1, or with an outdated CA bundle, can’t complete the handshake.
  • Traffic inspection. Some antivirus tools and corporate proxies intercept SMTP and present their own certificate.

Fix

  1. Match the port to the mode. Use port 587 with STARTTLS, or port 465 with implicit TLS. Don’t mix them.

    mailer.js
    const transporter = nodemailer.createTransport({
      host: 'smtp.emailit.com',
      port: 587,
      secure: false,     // STARTTLS on 587; set true only for port 465
      requireTLS: true,  // refuse to send if the upgrade fails
      auth: { user: 'emailit', pass: process.env.EMAILIT_API_KEY },
    });
  2. Use the exact host name. Set the host to smtp.emailit.com. Don’t use an IP address or an alias.

  3. Require encryption in your client. STARTTLS is offered on every plain-text port, but the relay doesn’t force it. Turn on your client’s “require TLS” option so credentials are never sent unencrypted.

  4. Test the handshake from the sending machine.

    Terminal
    openssl s_client -starttls smtp -connect smtp.emailit.com:587 -servername smtp.emailit.com
    openssl s_client -connect smtp.emailit.com:465 -servername smtp.emailit.com

    A healthy result shows subject=CN=smtp.emailit.com and Verify return code: 0 (ok). A different subject means something on your network is intercepting the connection.

  5. Update old runtimes. Upgrade the language runtime or OpenSSL and the system CA certificates if your client can’t negotiate TLS 1.2.

If the handshake succeeds but login fails, see Why does SMTP return 535 Authentication failed?. If you can’t connect at all, see Why does my SMTP connection time out?.

Still stuck?

Contact support or ask in Discord. Include the port, your client library and version, and the output of the openssl s_client command.

Was this page helpful?

Thanks for the feedback.

Thanks, we read every message.