How the message looks
530 5.7.0 Must issue a STARTTLS command first 530-5.7.0 Must issue a STARTTLS command first. For more information, go to https://support.google.com/mail/?p=WantAuthError 530 5.7.57 Client not authenticated to send anonymous mail during MAIL FROM

The three ports and what applies on each

Nearly every instance of this message is a wrong combination of port and encryption setting in the client:

  • 587 — submission with STARTTLS. The connection starts unencrypted and is upgraded with the STARTTLS command. In clients the setting is usually called “STARTTLS” or “TLS if available” — the latter is unsafe because it falls back silently.
  • 465 — submission with implicit TLS. Encryption is in place from the first byte. No STARTTLS may be sent here. In clients: “SSL/TLS”.
  • 25 — server to server. Not a path for end devices. Many connections block the port outbound anyway.

Entering 587 with encryption set to “none” produces exactly this message — the server demands TLS, the client does not offer it.

When the message comes from your own server

On a Postfix with smtpd_tls_security_level = encrypt or smtpd_tls_auth_only = yes this behaviour is intended: login only over an encrypted connection. That is correct and should not be turned off — a cleartext password across port 587 is precisely what it prevents.

On port 25, by contrast, encrypt does not belong. Foreign mail servers without TLS would be refused entirely; for server-to-server traffic may is the right setting, because a message delivered unencrypted still beats one not delivered at all.

Reproducing it

openssl s_client -starttls smtp -crlf -connect mail.yourprovider.com:587

If the TLS negotiation succeeds, the client is at fault. If openssl itself aborts, the server offers no STARTTLS on this port — then 465 or a different host is the right way.

Without encryption the capability shows up like this:

openssl s_client -crlf -connect mail.yourprovider.com:587 -quiet

After EHLO test the reply list must contain 250-STARTTLS. If that line is missing, the server cannot do it on this port.

The related variant

530 5.7.57 Client not authenticated to send anonymous mail is the same code with a different cause: what is missing there is not encryption but the login. The server accepts no mail for foreign recipients from unauthenticated clients — that is the boundary with 554 5.7.1 Relay access denied.

Find the cause in the actual message

Send or forward the affected email to hello@analyzemy.email. For that exact message the report shows which IP sent it, how SPF, DKIM and DMARC turned out, and where the chain breaks.

Analyze your email now

Last updated: · All error messages