[pfx] rejection of message due to mismatch in TLS versions
Linkcheck via Postfix-users <[email protected]> Fri, 5 Jun 2026 14:58:26 +0100
| Newsgroups | gmane.mail.postfix.user |
|---|---|
| Organization | Linkcheck |
| Message-ID | <[email protected]> |
Haven't seen this one before... Jun 5 10:02:22 bristolmail postfix/smtp[300641]: CF3B73F87F: to=<[email protected]>, relay=mx-01-eu-west-1.prod.hydra.sophos.com[63.33.39.203]:25, delay=10, delays=5.1/2.9/2.1/0.22, dsn=5.7.4, status=bounced (host mx-01-eu-west-1.prod.hydra.sophos.com[63.33.39.203] said: 550 5.7.4 XGEMAIL_0006 Command rejected : The rejection of the message occurred due to a mismatch in TLS versions between the configured TLS version is Preferred TLS 1.3 for the recipient: [email protected] and the sender: schoolhistoryscene.co.uk TLS version is not available (in reply to RCPT TO command)) I have SMTP TLS turned off to reduce attacks on the server but I wonder - should I enable, in main.cf (or master.cf smtp: ?): smtp_tls_security_level = may and smtp_tls_chain_files = /etc/letsencrypt/live/mail.bristolweb.net/privkey.pem /etc/letsencrypt/live/mail.bristolweb.net/fullchain.pem 2bounce_notice_recipient = [email protected] address_verify_map = proxy:btree:/var/lib/postfix/verify_cache address_verify_sender_ttl = 237m alias_database = hash:/etc/postfix/aliases alias_maps = hash:/etc/postfix/aliases append_dot_mydomain = no biff = no body_checks = pcre:/etc/postfix/body_checks.pcre bounce_notice_recipient = [email protected] bounce_queue_lifetime = 5d broken_sasl_auth_clients = yes compatibility_level = 3.6 confirm_delay_cleared = no delay_notice_recipient = [email protected] delay_warning_time = 2h disable_vrfy_command = yes error_notice_recipient = [email protected] header_checks = pcre:/etc/postfix/header_checks.pcre home_mailbox = Maildir/ html_directory = /usr/share/doc/postfix/html import_environment = MAIL_CONFIG MAIL_DEBUG MAIL_LOGTAG TZ XAUTHORITY DISPLAY LANG=C RESOLV_MULTI=on inet_interfaces = all inet_protocols = ipv4 internal_mail_filter_classes = bounce mailbox_size_limit = 0 maximal_queue_lifetime = 5d message_size_limit = 40960000 milter_connect_macros = j {daemon_name} {daemon_addr} v _ milter_default_action = accept milter_mail_macros = i {mail_addr} {client_addr} {client_name} {auth_authen} {auth_type} milter_protocol = 6 milter_rcpt_macros = i b mime_header_checks = pcre:/etc/postfix/mime_header_checks.pcre mua_milters = unix:/var/run/opendkim/opendkim.sock mydestination = $myhostname, localhost mydomain = bristolweb.net myhostname = mail.bristolweb.net mynetworks = 127.0.0.0/8 [::ffff:127.0.0.0]/104 [::1]/128 46.33.129.43 185.35.151.92 185.35.151.93 185.35.151.97 185.35.151.100 185.35.151.102 185.35.148.202 mynetworks_style = host myorigin = $myhostname non_smtpd_milters = unix:/var/run/opendkim/opendkim.sock notify_classes = software, delay, bounce, 2bounce, resource, protocol, data policy-spf_time_limit = 3600s queue_directory = /var/spool/postfix readme_directory = /usr/share/doc/postfix recipient_delimiter = + relay_domains = mysql:/etc/postfix/mysql-relay-domains.cf relay_recipient_maps = mysql:/etc/postfix/mysql_relay_recipients.cf relayhost = smtp_header_checks = pcre:/etc/postfix/smtp_header_checks.pcre smtp_host_lookup = dns smtp_tls_loglevel = 1 smtp_tls_note_starttls_offer = yes smtp_tls_security_level = none smtpd_banner = $myhostname ESMTP smtpd_client_restrictions = permit_mynetworks permit_sasl_authenticated reject_unknown_client_hostname reject_unauth_pipelining smtpd_data_restrictions = reject_unauth_pipelining, permit smtpd_delay_reject = yes smtpd_forbid_bare_newline = yes smtpd_forbid_bare_newline_exclusions = $mynetworks smtpd_forbid_unauth_pipelining = yes smtpd_hard_error_limit = 6 smtpd_helo_required = yes smtpd_helo_restrictions = permit_mynetworks permit_sasl_authenticated check_helo_access pcre:/etc/postfix/white_bypass.pcre check_client_access cidr:/etc/postfix/ip_check_whitelist reject_invalid_helo_hostname reject_non_fqdn_helo_hostname reject_unknown_helo_hostname check_client_access cidr:/etc/postfix/ip_check_blacklist check_helo_access pcre:/etc/postfix/helo_checks.pcre reject_unauth_pipelining permit smtpd_milters = unix:/var/run/opendkim/opendkim.sock, unix:/var/run/opendmarc/opendmarc.sock, unix:/var/run/spamass/spamass.sock, unix:/var/run/clamav/clamav-milter.ctl smtpd_recipient_restrictions = permit_mynetworks permit_sasl_authenticated reject_unauth_destination reject_non_fqdn_hostname reject_non_fqdn_recipient reject_unknown_recipient_domain reject_invalid_hostname reject_unauth_pipelining reject_unverified_recipient reject_unlisted_recipient check_recipient_access pcre:/etc/postfix/recipient_checks.pcre check_policy_service unix:private/policy-spf reject_rbl_client zen.spamhaus.org=127.0.0.[2..11] reject_rhsbl_sender dbl.spamhaus.org=127.0.1.[2..99] reject_rhsbl_helo dbl.spamhaus.org=127.0.1.[2..99] reject_rhsbl_reverse_client dbl.spamhaus.org=127.0.1.[2..99] warn_if_reject reject_rbl_client zen.spamhaus.org=127.255.255.[1..255] permit smtpd_relay_restrictions = permit_mynetworks, permit_sasl_authenticated, reject_unauth_destination smtpd_sasl_auth_enable = yes smtpd_sasl_local_domain = smtpd_sasl_path = private/auth smtpd_sasl_security_options = noanonymous nodictionary smtpd_sasl_type = dovecot smtpd_sender_restrictions = permit_mynetworks permit_sasl_authenticated reject_unauth_pipelining check_sender_mx_access cidr:/etc/postfix/sender_mx_access check_sender_access pcre:/etc/postfix/sender_whitelist.pcre reject_non_fqdn_sender reject_unknown_sender_domain reject_unlisted_sender check_sender_access pcre:/etc/postfix/sender_checks.pcre smtpd_soft_error_limit = 4 smtpd_tls_chain_files = /etc/letsencrypt/live/mail.bristolweb.net/privkey.pem /etc/letsencrypt/live/mail.bristolweb.net/fullchain.pem smtpd_tls_loglevel = 1 smtpd_tls_received_header = yes smtpd_tls_security_level = may smtpd_use_tls = yes smtputf8_enable = no strict_rfc821_envelopes = yes transport_maps = mysql:/etc/postfix/mysql_transport.cf unknown_address_reject_code = 553 unknown_client_reject_code = 571 unknown_hostname_reject_code = 571 unverified_recipient_reject_code = 550 virtual_alias_maps = mysql:/etc/postfix/mysql-virtual-alias-maps.cf virtual_mailbox_domains = mysql:/etc/postfix/mysql-virtual-mailbox-domains.cf virtual_mailbox_maps = mysql:/etc/postfix/mysql-virtual-mailbox-maps.cf virtual_transport = lmtp:unix:private/dovecot-lmtp _______________________________________________ Postfix-users mailing list -- [email protected] To unsubscribe send an email to [email protected]