Security & Abuse

TLS for SMTP: What It Protects and What It Does Not

Hop encryption. Not E2E. Not placement. Leave TLS on.

MailerZ editorial · Secuno LLC16 min read

SMTP TLS protects the hop in transit between two servers or between your client and MailerZ. It is not end-to-end encryption. It does not hide Header From. It does not fix leftover MX. It is not an inbox-placement SLA. AUTH and a mapped From still decide whether we accept the message. Close inbound 25. Copy the dashboard port. Do not disable TLS to “see the problem.”

A padlock in a client UI is not proof of exclusive MX, not proof of inbox placement, and not a certification. Certificate warnings mean stop and fix the hostname. STARTTLS versus implicit TLS must match the dashboard port. WordPress, Gmail send-as, Outlook, and VPS scripts all fail the same way when that pair is wrong. Do not install Postfix to debug. Do not open 25. Isolate SMTP so a leaked password is one zone. Rotate if someone unchecked SSL. Agency does not buy stronger TLS. It buys domains, aliases, seats, outgoing caps, and store days. Confirm pricing. Not SOC 2. Not HIPAA.

TLS protects the SMTP hop, not end-to-end or Header From
Hop in transit. Not E2E. Not Header From. Not an inbox SLA. Copy the dashboard host. Leave encryption on. AUTH and mapped From still decide accept or 550.

Quick answer for smtp tls security

Use dashboard SMTP. Product: features, security, send and reply. IETF RFC 5321 — Simple Mail Transfer Protocol. Settings knobs: the STARTTLS vs TLS article. Helpful: people-first content. Outlook device SMTP: Microsoft Learn — Send email from a device or app using Microsoft 365.

Confirm pricing. Free no send-as. Solo $40/yr. Starter $8/$80. Business $19/$190. Agency $39/$390. No SOC 2. No inbox SLA.

The user problem and the decision criteria

Buyers hear “we use TLS” and stop. Attackers still see metadata at rest in Gmail. Operators disable TLS and leak passwords on the LAN. The useful statement is “this hop is encrypted.” The useless statement is “email is encrypted.”

TLS versus other controls
QuestionIf yesIf no
Client uses dashboard port with TLS?Hop to us is in the intended mode.Fix the client. Do not open 25.
Expecting E2E to the reader?Wrong product class.Good. You understand hops.
TLS therefore inbox?False. Placement is separate.Good.
Unmapped From?550 even on TLS.Mapped + AUTH.

Say hop encryption on the sales call. Do not say sealed email. Do not say inbox guaranteed. Do not hang SOC 2 or HIPAA on a padlock. Copy the dashboard. Match the TLS mode to the port. Fix AUTH without turning encryption off. Close inbound 25. Isolate SMTP. Rotate after a leak. Exclusive MX remains an inbound ticket. HOLD remains unknown inbound. Mapped From remains outbound authorization. Keep those names so a certificate icon does not swallow the incident. Onward hops to Gmail may or may not use TLS. You cannot audit every later hop from the dashboard. That is why hop-scoped language matters. A founder who asks whether Agency buys stronger TLS gets a no. Agency buys capacity. Confirm live cards. Free still cannot send-as. 550 on TLS is still authorization.

Technical mail flow

Your app connects, upgrades or starts TLS, AUTH, MAIL FROM. We may use TLS onward to the destination if that MX offers it. Each hop is a new decision. A later hop in cleartext is possible on the internet. That is why TLS is hop-scoped. IETF RFC 5321 — Simple Mail Transfer Protocol does not promise a confidential path to the human.

STARTTLS versus implicit TLS; AUTH still required
STARTTLS vs implicit. AUTH still required. Not Header From.

Envelope SRS still happens. Header From stays the sender. TLS does not rewrite identity. DKIM signs content; TLS does not replace DKIM. IETF RFC 6376 — DomainKeys Identified Mail (DKIM).

Step-by-step setup and decision path

  1. Copy dashboard host and port

    Do not guess 25. Do not copy a competitor port.

  2. Enable TLS in the client as documented

    STARTTLS or implicit—match the port. See the settings article.

  3. AUTH with the zone’s user

    TLS without AUTH is not verified send.

  4. Send one unique probe

    History 250. Delete the script.

  5. Keep 25 closed inbound

    TLS on a public relay is still a relay.

  6. Do not disable TLS to debug AUTH

    Fix the password. Rotate if you already leaked it.

TLS is not an inbox SLA; AUTH remains required
Not an inbox SLA. AUTH still required.

Failure modes and proof

TLS-related failure, cause, action
What you seeLikely causeProof
Certificate warningWrong hostDashboard hostname
TimeoutWrong port or blocked egressDashboard port
550 on TLSFrom or planNot a TLS bug
Cleartext debugYou turned TLS offTurn it back on. Rotate
Spam folderPlacementNot a TLS SLA

Proof is a TLS session to the named host plus a 250. A padlock icon in a random client is not exclusive MX.

MailerZ workflow and product boundary

Authenticated SMTP plus inbound MX. Envelope SRS. Header From never rewritten. Not IMAP. Not an open relay. 550 unhosted. Free 1/3/14-day/HOLD/no send-as. Solo $40/yr. Starter $8/$80. Business $19/$190. Agency $39/$390. Confirm /pricing. No SOC 2. No inbox SLA. No HIPAA.

Cost, alternatives, and trade-offs

Spend versus hop TLS
ChoiceWhat you getWhat you give up
Dashboard TLS SMTPA protected submit hopThe myth of E2E email
S/MIME or PGPContent crypto you operateThis hop as the encryptor
Workspace onlyTheir transport. Quote liveGmail-as-store + this hop if that was the job

Time is a line item. Copying the port costs less than a week of opportunistic cleartext.

What TLS protects

Confidentiality and integrity of the SMTP session against a network observer on that hop: AUTH password, envelope, and DATA in flight. That is worth doing. It is why you do not debug with TLS off on coffee-shop Wi-Fi.

What TLS does not protect

The destination mailbox at rest. The next hop if it is cleartext. Header From visibility to the recipient. Leftover MX splits. Inbox placement. GDPR lawful basis. Open relays. Catch-all noise. A leaked SMTP user. Those need other controls.

STARTTLS versus implicit TLS

STARTTLS upgrades a plain connection. Implicit TLS starts encrypted on a dedicated port. Match what the dashboard says. A mismatch looks like a hang. The dedicated settings article covers client checkboxes. This page is the security boundary: hop versus E2E.

Two-factor on destinations. HOLD review. Exclusive MX is inbound. Night operators who “turn off SSL” recreate password leaks. Rotate if they did.

If a second operator needs the order, send this page plus send-reply and the STARTTLS settings post. Dashboard port. AUTH. Mapped From. TLS on. No E2E fairy tale.

The artifacts that close smtp tls security are a TLS submit to the named host and a 250. Everything else is a padlock you misunderstood.

Who can still read the message

Anyone with access to the destination mailbox can read the message at rest. Gmail operators, a stolen cookie, a shared family computer, a forwarded copy, a legal process at the destination provider. SMTP TLS on the hop to MailerZ does not follow the bytes into that store. If you needed end-to-end confidentiality, you would operate S/MIME or PGP with the recipient. We do not sell that. We do not pretend TLS is that.

Operators who can open MailerZ history or HOLD also see operational copies during the store window. Free is fourteen days. Paid is ninety. Confirm pricing. That is why you do not paste bodies into tickets. The GDPR article names the classes. This page names the boundary: hop encryption is not a sealed drop.

A network observer on a later hop—between us and Gmail, or between Gmail and a user’s phone on cleartext IMAP, which is their problem—may see content if that hop is not encrypted. You cannot audit every later hop from our dashboard. Do not write “email is encrypted” on a sales deck because our submit port uses TLS.

Header From is visible to the recipient by design. We never rewrite it. TLS does not hide who the message claims to be from. DKIM can authenticate the domain. TLS does not replace DKIM. IETF RFC 6376 — DomainKeys Identified Mail (DKIM).

TLS does not replace AUTH

An encrypted session that offers an unmapped From still gets 550 5.7.1. An encrypted session on Free still cannot send-as. An encrypted open listener on port 25 is still a listener. Verified sending is AUTH plus a From we know. TLS is how the password should travel. They stack. They do not substitute.

Disabling TLS “to see the AUTH error” puts the password on the path in cleartext. Fix the user, password, host, and port instead. Rotate if you already leaked it on coffee-shop Wi-Fi. Isolate SMTP per client so one leak is one zone.

Certificate warnings usually mean the wrong hostname. Copy the dashboard host. Do not click through a warning to a name you invented. A man-in-the-middle on a wrong host is exactly what TLS is trying to show you.

Ports, certificates, and wrong hosts

Implicit TLS and STARTTLS are different client modes. The dashboard tells you which port matches which mode. A mismatch looks like a hang or a protocol error. The STARTTLS versus TLS settings article covers checkboxes. This page adds: picking a competitor’s port from a blog is how you send passwords to the wrong place or fail AUTH for an hour.

Do not use inbound 25 on your VPS as a “TLS test.” Close inbound 25. You are a client. You submit out. Microsoft’s device SMTP notes are a different vendor’s UX—Microsoft Learn — Send email from a device or app using Microsoft 365—then use our dashboard values.

Timeouts are often egress filters, not TLS philosophy. Cloud security groups that allow 25 but not the dashboard port will fail in a way that looks like encryption. Open the documented port. Do not “fix” it by installing Postfix.

Onward hops you do not control

After we accept your submit, we deliver toward the recipient MX. That session may use TLS if the other side offers it. If they do not, the onward hop may be clear. We will not promise a TLS SLA to every destination on the internet. We will not promise inbox placement because TLS was on. Placement is a different ticket. Leftover MX is a different ticket.

Inbound to us from random senders is the same story in reverse. Some senders offer STARTTLS. Some do not. Exclusive MX still matters. TLS does not delete a leftover Google row.

Claims TLS cannot carry

TLS is not SOC 2. TLS is not HIPAA. TLS is not ISO 27001. TLS is not an inbox SLA. TLS is not GDPR lawful basis. TLS is not “anonymous email.” Cite security for controls without badges. Cite privacy pages for processing. Do not hang those words on a padlock icon.

Night operators who turn SSL off in a plugin recreate password leaks. Two-factor on destinations. HOLD review. Exclusive MX for inbound. Mapped From for outbound. Filename screenshots with the zone if you are proving a hop.

If a second operator needs the order, send this page plus send-reply, the STARTTLS settings post, and the open-relay article. Dashboard port. TLS on. AUTH. Mapped From. Hop-scoped expectations.

The artifacts that close smtp tls security are a TLS session to the named host, AUTH, and one 250. Everything else is a padlock that does not mean what the slide said.

MTA-STS, DANE, and what we are not claiming

The industry has mechanisms that push inbound SMTP toward TLS and authenticated MX: MTA-STS, DANE, and policy lists at large receivers. Those are inbound-to-a-domain stories. Do not write them onto MailerZ outbound submit unless /security or the dashboard documents a specific setting. This article will not invent a policy file we have not published.

STARTTLS downgrade on the public internet is a known class of attack on opportunistic encryption. Using the dashboard’s implicit TLS port when that is what we publish reduces that class on the hop you control. It does not encrypt Gmail at rest. It does not fix leftover MX. It does not make 550 go away.

Receivers that require TLS from senders may reject a later hop that is clear. That reject is their policy. It is not an inbox SLA we sell. Read the SMTP line. Do not dual MX to dodge it.

Gmail, Outlook, WordPress, and VPS clients

Gmail send-as should use the dashboard host, port, and TLS mode Google’s UI asks for—then our values, not a Gmail password in a plugin. Google Gmail Help — Send mail from a different address is UX. Outlook device SMTP is the same pattern—Microsoft Learn — Send email from a device or app using Microsoft 365. WordPress SMTP plugins that default to “none” for encryption are a leak waiting for a staging URL. VPS scripts should not print the password. Delete the probe script after one 250.

Free has no send-as. TLS on a 550 is still a 550. Pay the card that includes send-as. Confirm /pricing. Solo forty dollars a year. Starter eight or eighty. Business nineteen or one hundred ninety. Agency thirty-nine or three hundred ninety.

Shared env across clients means one TLS session can send as the wrong From if the user is shared. Isolate credentials. TLS does not namespace tenants.

Debugging without turning TLS off

If AUTH fails, check user, password, host, port, and plan. If the certificate name mismatches, fix the host. If the connection hangs, fix egress or the STARTTLS versus implicit mode. If history is empty, you never reached us. If history is 550, read the reason. None of those steps require cleartext.

Packet captures on your own host can still contain passwords if you disabled TLS. Prefer application logs that redact secrets. Rotate after any capture you stored.

Night operators who “just uncheck SSL” in a plugin recreate the leak. Write TLS on the ticket as a requirement, not a suggestion. Two-factor on destinations. Exclusive MX is inbound. Mapped From is outbound. HOLD is unknown inbound. Keep the tickets named.

People-first debug notes quote the SMTP line and the host: helpful content. A padlock emoji in Slack is not evidence.

The artifacts that close smtp tls security are a TLS submit to the dashboard host, AUTH, mapped From, and one 250. MailerZ can encrypt the session you open to us. It cannot encrypt the destination mailbox or promise the inbox.

What to say on a sales call without lying

You may say the submit hop to MailerZ uses TLS when the client uses the dashboard host and port. You may say AUTH and a mapped From are still required. You may say Header From is not rewritten. You may not say email is end-to-end encrypted. You may not say TLS means inbox. You may not say TLS is SOC 2 or HIPAA. You may not say TLS deletes leftover MX. You may not say TLS makes Free able to send-as.

If the buyer needs a sealed message, they need a content-crypto product they operate with the recipient. If they need a hosted archive, they need a suite. Quote those live. MailerZ is inbound MX plus authenticated SMTP. Envelope SRS. Store windows of fourteen or ninety days. Confirm pricing. Agency buys capacity, not a padlock upgrade.

Engineers should copy the dashboard, leave TLS on, send one unique probe, delete the script, and close inbound 25. That is the same stack as verified sending. TLS is one layer. AUTH is another. From is another. MX exclusivity is inbound. HOLD is unknown inbound. Keep the names straight on the ticket.

Night operators who uncheck SSL recreate a password leak. Rotate. Filename the client settings with the zone. Isolate SMTP so one leak is one client. Two-factor on destinations. Re-query MX after registrar tiles if you also cut inbound.

A certificate warning is a stop, not a click-through. Wrong host means you may be talking to someone else. Copy the dashboard hostname character for character. Do not use an IP to skip the name check unless the product documented that and you understand you lost name verification. Most small teams should never do that.

WordPress, Gmail send-as, Outlook, and VPS scripts all fail the same way when TLS mode and port disagree. Fix the pair. Do not disable encryption. Do not open 25. Do not install Postfix. Do not blame leftover MX for an AUTH timeout. Those are different tickets with different proofs.

If a founder asks whether paying Agency buys stronger TLS, the answer is no. Agency buys domains, aliases, seats, outgoing caps, and store days. Confirm pricing. TLS is on the submit hop when you use the dashboard correctly on any paid send-as plan. Caps are not an inbox SLA. Not SOC 2. Not HIPAA.

FAQ

What is the safest way to handle smtp tls security?

Use the dashboard’s SMTP host and port so the hop to MailerZ is TLS. Understand that TLS protects that hop in transit. It is not end-to-end encryption to the final reader. It does not rewrite or hide Header From. It is not an inbox SLA. AUTH and a mapped From are still required. Close inbound 25 on app hosts.

Does this require a new mailbox?

No. TLS is transport. The store is still Gmail or Outlook. MailerZ is not IMAP. A suite mailbox does not make SMTP TLS end-to-end.

Will it work with Gmail or Outlook?

Clients should offer STARTTLS or implicit TLS as the vendor documents. Self-send still lies about inbound MX. Free has no send-as. Confirm /pricing.

What DNS records are involved?

TLS for SMTP is not a TXT you invent. MTA-STS and DANE exist in the industry; do not claim we published them unless /security says so. MX remains RFC 5321. SPF/DKIM/DMARC are authentication, not TLS.

What should I test before production?

Copy dashboard port. Send one authorized message. Confirm history 250. Do not disable TLS ‘to debug.’ Do not open 25. See STARTTLS vs TLS settings if you need client knobs.

Key takeaways

  • TLS protects the hop in transit between your client and MailerZ when you use the dashboard host and port.
  • It is not end-to-end encryption. It does not hide Header From. It is not an inbox SLA.
  • AUTH and a mapped From are still required. 550 5.7.1 still applies on TLS.
  • Copy the dashboard host and port. Match STARTTLS or implicit TLS to that port.
  • Do not disable TLS to debug AUTH. Do not click through a certificate warning.
  • Close inbound 25. You are a client, not an MTA. Do not install Postfix to test.
  • Confirm pricing. Free has no send-as. Agency does not buy stronger TLS. Not SOC 2. Not HIPAA.
  • Isolate SMTP so a leaked password is one zone. Rotate if someone unchecked SSL. Filename client settings with the zone so agencies do not reuse a host from last month. Re-query leftover MX only if inbound is also in scope.

Conclusion and next action

If you need SMTP TLS, use the hop we publish and keep expectations hop-scoped. MailerZ can encrypt the session you open to us. It cannot encrypt Gmail at rest or promise the inbox. Start free for inbound, paid when you submit on TLS as a mapped From. Copy the dashboard host and port. Leave encryption on. Do not click through a certificate warning.

AUTH and a mapped From still decide whether we accept the message. TLS does not replace them. TLS does not delete leftover MX. TLS does not make Free able to send-as. TLS is not SOC 2, HIPAA, or an inbox SLA. Agency does not buy stronger TLS. It buys capacity. Confirm pricing.

Close inbound 25. Do not install Postfix to debug. Isolate SMTP so a leaked password is one zone. Rotate if someone unchecked SSL. Two-factor on destinations. Exclusive MX is inbound. HOLD is unknown inbound. Keep those tickets named so a padlock icon does not swallow the incident.

Ready to submit on TLS

Start free for inbound, paid for dashboard SMTP.

Copy the port. Leave TLS on. Sign in if the domain is already there.

Review when SMTP ports or TLS policy change. Author: MailerZ editorial, Secuno LLC.