How the message looks
Cannot start TLS: handshake failure postfix/smtp[1234]: SSL_connect error to mx.example.com[203.0.113.5]:25: -1 TLS is required, but was not offered by host mx.example.com[203.0.113.5]

The four usual causes

  1. No shared protocol version. Current servers refuse TLS 1.0 and 1.1, while older peers cannot do TLS 1.2. If no version is left, the handshake ends immediately. This is now the single most common cause.
  2. No shared cipher suite. Rarer, but possible when one side is limited to modern AEAD suites and the other offers only old CBC ones.
  3. An incomplete certificate chain. The server sends only its own certificate without the intermediate. Some clients fill that in themselves, others abort. A test that works locally but not from outside almost always points here.
  4. A middlebox interferes. Firewalls with SMTP inspection mangle the EHLO response or the STARTTLS command in order to read along. Recognisable when the server offers no STARTTLS from outside but does so on the machine itself.

Reproducing it yourself

The handshake can be tested on its own, without sending a message:

openssl s_client -starttls smtp -connect mx.example.com:25 -crlf Worth reading in the output: Protocol / Cipher → what was negotiated Verify return code → 0 (ok) or a chain error Certificate chain → does it include the intermediate?

If there is no output at all, the peer does not support STARTTLS or something in between strips it. A plaintext EHLO shows whether 250-STARTTLS is announced in the first place.

When TLS is mandatory

The message “TLS is required, but was not offered” is a different case: here your side has configured mandatory TLS while the peer offers none. That may be a deliberate policy — or an MTA-STS policy or DANE record demanding encryption while the target server currently fails to provide it.

Find the cause in the actual message

Send or forward the affected email to hello@analyzemy.email. For that exact message the report shows which IP sent it, how SPF, DKIM and DMARC turned out, and where the chain breaks.

Analyze your email now

Last updated: · All error messages