On this page
What TLS does for email
TLS (the modern successor to SSL) encrypts connections between mail clients and servers, and between servers. It applies in several places: submission (your users or apps sending to your server), server-to-server delivery over SMTP, IMAP for reading mail, and webmail over HTTPS.
Between servers, SMTP uses STARTTLS, which upgrades a connection to encryption when both sides support it. By default this is opportunistic: if encryption fails, mail may be sent in the clear. Standards such as MTA-STS let you require encryption for mail sent to your domain.
Signs your TLS needs attention
- Mail clients show certificate warnings when connecting.
- Gmail displays a warning that a message wasn’t encrypted.
- A certificate expired and nobody noticed until users complained.
- Your server still accepts old protocol versions or weak ciphers.
- The certificate name doesn’t match the hostname clients connect to.
Who needs this work
Anyone running their own mail server needs TLS configured correctly, and it is worth revisiting on servers set up a few years ago. It matters most for:
- Businesses whose staff connect to mailboxes from phones and laptops outside the office.
- Organisations exchanging sensitive documents with partners who expect encrypted delivery.
- Self-hosted sending servers, where encryption is part of looking like a well-run operation to receivers.
- Domains that want MTA-STS to protect inbound mail from downgrade attacks.
If you use a hosted mail suite, most of this is handled by the provider, though MTA-STS and TLS-RPT still need records on your own domain.
What’s included
- Certificates issued for each mail hostname, typically through Let’s Encrypt, with automatic renewal.
- TLS on SMTP (STARTTLS), submission on port 587 and implicit TLS on port 465 where needed.
- TLS on IMAP and POP3 if used, and HTTPS on webmail and admin panels.
- Modern protocol versions and sensible cipher choices.
- Opportunistic TLS for outbound delivery, with enforced TLS for specific partners where agreed.
- MTA-STS policy and DNS record so senders require encryption to your domain.
- TLS-RPT so you receive reports of failed encrypted connections.
- Renewal hooks so every service reloads the new certificate automatically.
How we deliver it
- Inventory every hostname and port your mail services use.
- Issue certificates and configure each service to use them.
- Set protocol and cipher policy suited to your clients and partners.
- Test every port externally for certificate validity, name match and protocol support.
- Publish MTA-STS in testing mode, review TLS-RPT reports, then move to enforce.
- Force a renewal to prove the whole chain works, including service reloads.
- Document hostnames, certificate paths and renewal checks.
Where partners require enforced TLS for specific domains, we configure per-destination policies so mail to them is never delivered unencrypted, while other destinations continue to use opportunistic TLS.
MTA-STS and TLS-RPT in practice
MTA-STS uses a TXT record at _mta-sts.yourdomain.com and a policy file served over HTTPS from an mta-sts subdomain. It tells sending servers which MX hosts are valid and whether TLS is required. TLS-RPT uses a TXT record at _smtp._tls.yourdomain.com to request daily reports. Starting in testing mode means problems show up in reports before any mail is refused.
What affects timeline and cost
- Number of hostnames, services and domains.
- Legacy clients or partners that need older protocols.
- Whether MTA-STS and TLS-RPT are included.
- Suite-specific certificate handling, for example in Mailcow.
Common mistakes
Renewing a certificate on disk while the mail service keeps serving the old one from memory. A certificate for the website hostname but not the mail hostname. Jumping straight to MTA-STS enforce mode with an MX host missing from the policy. Trusting the configuration file instead of testing from outside.
Related: mail server installation, DNS configuration, all email infrastructure services, the guide, and contact.
Frequently asked questions
Is SSL the same as TLS?
TLS replaced SSL, but “SSL” is still widely used to mean the same thing. Modern servers should use current TLS versions only.
Do we need a paid certificate?
Usually not. Free certificates from Let’s Encrypt are trusted by mail clients and servers, as long as renewal is automated and tested.
What is MTA-STS for?
It lets your domain require encrypted delivery from other servers and specifies which MX hosts are legitimate, reducing the risk of interception.
Will enforcing TLS block any mail?
It can if a sending server can’t negotiate TLS correctly. That’s why we start in testing mode and read the reports first.
Which ports should our mail server use?
Port 25 for server-to-server delivery, 587 with STARTTLS for authenticated submission, and optionally 465 for implicit TLS. IMAP uses 993 with TLS.
Talk to us about ssl & tls configuration
Encrypted transport correctly configured for SMTP, IMAP and webmail.