Documentation

STARTTLS and certificate errors

Fix TLS negotiation without weakening message transport.

Use explicit TLS

Select STARTTLS or explicit TLS on port 587, not implicit SSL/TLS on port 465. Use the hostname rather than a hard-coded IP so certificate validation can succeed.

Check old devices

Correct the device clock, update firmware, install required certificate authorities, and confirm modern TLS support. Some old devices advertise TLS but cannot negotiate current protocols.