KumoMTA internal: failed to connect to any candidate hosts: tls policy is Required but STARTTLS

yeah my point is that I don’t think it’s a firewall-type issue because it should fail on their as well?

whereas Gmail doesn’t even OFFER it on the SMTP connection

I’m honestly at a massive loss, I’ve never seen something like this before. Blacklisted IP maybe?

Yeah, I wonder if the IP of the host that doesn’t offer is consistent so it could be omitted from rotation.

oh like try a different Gmail endpoint? I can give it a shot, but based on the full error above it appears to be all of them

Strange.

huh. what’s weird is it inboxed gmail using SWAKS on that IP/domain

(I was thinking maybe it was related to like a really bad IP reputation or something…but apparently not?)

I guess I could configure Kumo to not require startTLS, but that feels like a bad idea. I thought Gmail required it so I’m shocked this worked

Yeah I’d say your easiest fix is to go to opportunistic.

https://apps.google.com/supportwidget/articlehome?article_url=https%3A%2F%2Fsupport.google.com%2Fa%2Fanswer%2F81126%3Fvisit_id%3D638598709632343256-3471037042&assistant_id=generic-unu&product_context=81126&product_name=UnuFlow&trigger_context=a

yeah, supposedly the requirement to use TLS started in December

oppertunistic means it won’t REQUIRE the StartTLS response in Kumo right? so it would work just without TLS

If there’s TLS advertised it will use it, otherwise plaintext.

I think turning off tls is the wrong move here. Need to figure out why it is not being advertised to you

I agree, I just wanted to understand the options

Is there a scenario where the cause of it not being advertised is in our control?

I have a hunch, but need to wait for the client to get back to me

it’s not in our control

if it’s the case, KumoProxy may be the answer. They’re doing some routing funkiness here. and I bet Gmail doesn’t like it.

it’s possible that they decide not to show it based on IP and/or EHLO domain