The three ports and what applies on each
Nearly every instance of this message is a wrong combination of port and encryption setting in the client:
- 587 — submission with STARTTLS. The connection starts unencrypted and is upgraded with the
STARTTLScommand. In clients the setting is usually called “STARTTLS” or “TLS if available” — the latter is unsafe because it falls back silently. - 465 — submission with implicit TLS. Encryption is in place from the first byte. No
STARTTLSmay be sent here. In clients: “SSL/TLS”. - 25 — server to server. Not a path for end devices. Many connections block the port outbound anyway.
Entering 587 with encryption set to “none” produces exactly this message — the server demands TLS, the client does not offer it.
When the message comes from your own server
On a Postfix with smtpd_tls_security_level = encrypt or smtpd_tls_auth_only = yes this behaviour is intended: login only over an encrypted connection. That is correct and should not be turned off — a cleartext password across port 587 is precisely what it prevents.
On port 25, by contrast, encrypt does not belong. Foreign mail servers without TLS would be refused entirely; for server-to-server traffic may is the right setting, because a message delivered unencrypted still beats one not delivered at all.
Reproducing it
If the TLS negotiation succeeds, the client is at fault. If openssl itself aborts, the server offers no STARTTLS on this port — then 465 or a different host is the right way.
Without encryption the capability shows up like this:
After EHLO test the reply list must contain 250-STARTTLS. If that line is missing, the server cannot do it on this port.
The related variant
530 5.7.57 Client not authenticated to send anonymous mail is the same code with a different cause: what is missing there is not encryption but the login. The server accepts no mail for foreign recipients from unauthenticated clients — that is the boundary with 554 5.7.1 Relay access denied.