ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Office 365 SMTP server not advertising StartTLS

    IT Discussion
    office 365 smtp
    7
    20
    3.1k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      flaxking
      last edited by

      The logs from two separate email libraries show smtp.office365.com not offering StartTLS

      log #1

      01/16/19 13:16:09   Opening Socket.
      Performing DNS lookup: smtp.office365.com
      Connecting to: 40.101.128.18
      220 YTXPR0101CA0068.outlook.office365.com ESMTP Service ready
      EHLO domain.com
      250-Requested mail action okay, completed
      250-SIZE 20000000
      250-8BITMIME
      250 OK
      STARTTLS
      503 Bad sequence of commands
      503 Bad sequence of commands
      QUIT
      221 Service closing transmission channel
      

      log #2

      Connected to smtp://smtp.office365.com:587/?starttls=always
      S: 220 YTXPR0101CA0071.outlook.office365.com ESMTP Service ready
      C: EHLO [10.25.124.141]
      S: 250-Requested mail action okay, completed
      S: 250-SIZE 20000000
      S: 250-8BITMIME
      S: 250 OK
      

      However, following the same commands via telnet shows StartTLS offered

      220 BYAPR03CA0002.outlook.office365.com Microsoft ESMTP MAIL Service ready at Wed, 16 Jan 2019 23:11:15 +0000
      EHLO domain.com
      250-BYAPR03CA0002.outlook.office365.com Hello [x.x.x.x]
      250-SIZE 157286400
      250-PIPELINING
      250-DSN
      250-ENHANCEDSTATUSCODES
      250-STARTTLS
      250-8BITMIME
      250-BINARYMIME
      250-CHUNKING
      250 SMTPUTF8
      

      This is on Windows. I haven't tried what happens on a different computer, but I'm wondering what could possibly be the difference happening here that's causing the server to respond differently?

      1 Reply Last reply Reply Quote 2
      • JaredBuschJ
        JaredBusch
        last edited by

        Whatever app you are using is doing something different? Because it has always work for e when using telnet.

        DashrenderD 1 Reply Last reply Reply Quote 0
        • DashrenderD
          Dashrender @JaredBusch
          last edited by

          @JaredBusch said in Office 365 SMTP server not advertising StartTLS:

          Whatever app you are using is doing something different? Because it has always work for e when using telnet.

          I'm not sure this is helpful... His Telnet IS showing it, the logs from his mail server are not.

          1 Reply Last reply Reply Quote 0
          • F
            flaxking
            last edited by

            Tested using same application but on different computer and network, works without any issue.

            Need to verify whether or not it's only happening on one of the computers on their network.

            1 Reply Last reply Reply Quote 0
            • wrx7mW
              wrx7m
              last edited by

              Could it be TLS 1.2 is not set as the default on the client system? If it is Windows 7, you need to adjust some registry entries.

              F 1 Reply Last reply Reply Quote 0
              • F
                flaxking @wrx7m
                last edited by

                @wrx7m said in Office 365 SMTP server not advertising StartTLS:

                Could it be TLS 1.2 is not set as the default on the client system? If it is Windows 7, you need to adjust some registry entries.

                The one email library will only use a maximum of TLS 1.0. And it is before the TLS handshake, so I wouldn't think that TLS version would be a consideration yet.

                wrx7mW 1 Reply Last reply Reply Quote 0
                • wrx7mW
                  wrx7m @flaxking
                  last edited by

                  @flaxking said in Office 365 SMTP server not advertising StartTLS:

                  @wrx7m said in Office 365 SMTP server not advertising StartTLS:

                  Could it be TLS 1.2 is not set as the default on the client system? If it is Windows 7, you need to adjust some registry entries.

                  The one email library will only use a maximum of TLS 1.0. And it is before the TLS handshake, so I wouldn't think that TLS version would be a consideration yet.

                  OK, because they started forcing TLS 1.2 back in October.

                  F 1 Reply Last reply Reply Quote 0
                  • F
                    flaxking @wrx7m
                    last edited by

                    @wrx7m said in Office 365 SMTP server not advertising StartTLS:

                    @flaxking said in Office 365 SMTP server not advertising StartTLS:

                    @wrx7m said in Office 365 SMTP server not advertising StartTLS:

                    Could it be TLS 1.2 is not set as the default on the client system? If it is Windows 7, you need to adjust some registry entries.

                    The one email library will only use a maximum of TLS 1.0. And it is before the TLS handshake, so I wouldn't think that TLS version would be a consideration yet.

                    OK, because they started forcing TLS 1.2 back in October.

                    Nope, they've updated that notice

                    wrx7mW 1 Reply Last reply Reply Quote 0
                    • wrx7mW
                      wrx7m @flaxking
                      last edited by

                      @flaxking Guess we are thinking of different notices... https://support.microsoft.com/en-us/help/4057306/preparing-for-tls-1-2-in-office-365

                      F 1 Reply Last reply Reply Quote 0
                      • F
                        flaxking @wrx7m
                        last edited by

                        @wrx7m "Note This doesn't mean Office 365 will block TLS 1.0 and 1.1 connections. There is no official date for disabling or removing TLS 1.0 and 1.1 in the TLS service for customer connections."

                        wrx7mW 1 Reply Last reply Reply Quote 0
                        • wrx7mW
                          wrx7m @flaxking
                          last edited by

                          @flaxking Gotcha. But, it has caused issues depending on how you are connecting and what you are connecting with. I had issues connecting with Windows 7 and Outlook and was told by support to apply registry fix and make sure a certain update was applied.

                          1 Reply Last reply Reply Quote 0
                          • DashrenderD
                            Dashrender
                            last edited by

                            Isn't the list of SMTP commands given before there is any attempt to bring up a TLS tunnel? Assuming my understanding of that is correct - then it shouldn't matter what version of TLS is supported - the advertising of STARTTLS should still be in the list - and the library's aren't seeing them - right?

                            1 Reply Last reply Reply Quote 0
                            • F
                              flaxking
                              last edited by

                              From what I heard from our tech, it sounds like the company's UTM was messing with it.

                              scottalanmillerS dbeatoD 2 Replies Last reply Reply Quote 0
                              • scottalanmillerS
                                scottalanmiller @flaxking
                                last edited by

                                @flaxking said in Office 365 SMTP server not advertising StartTLS:

                                From what I heard from our tech, it sounds like the company's UTM was messing with it.

                                That's quite possible. UTMs can introduce a lot of problems.

                                DashrenderD 1 Reply Last reply Reply Quote 0
                                • DashrenderD
                                  Dashrender @scottalanmiller
                                  last edited by

                                  @scottalanmiller said in Office 365 SMTP server not advertising StartTLS:

                                  @flaxking said in Office 365 SMTP server not advertising StartTLS:

                                  From what I heard from our tech, it sounds like the company's UTM was messing with it.

                                  That's quite possible. UTMs can introduce a lot of problems.

                                  LOL I was going to say the same thing...

                                  1 Reply Last reply Reply Quote 0
                                  • dbeatoD
                                    dbeato @flaxking
                                    last edited by

                                    @flaxking said in Office 365 SMTP server not advertising StartTLS:

                                    From what I heard from our tech, it sounds like the company's UTM was messing with it.

                                    Which UTM? Hopefully not SOnicwall in this case.

                                    scottalanmillerS 1 Reply Last reply Reply Quote 0
                                    • scottalanmillerS
                                      scottalanmiller @dbeato
                                      last edited by

                                      @dbeato said in Office 365 SMTP server not advertising StartTLS:

                                      @flaxking said in Office 365 SMTP server not advertising StartTLS:

                                      From what I heard from our tech, it sounds like the company's UTM was messing with it.

                                      Which UTM? Hopefully not SOnicwall in this case.

                                      Hopefully it IS SonicWall, so that all these stupid issues can be isolated to one bad vendor rather than sprawling across the industry.

                                      dbeatoD 1 Reply Last reply Reply Quote 1
                                      • dbeatoD
                                        dbeato @scottalanmiller
                                        last edited by

                                        @scottalanmiller said in Office 365 SMTP server not advertising StartTLS:

                                        @dbeato said in Office 365 SMTP server not advertising StartTLS:

                                        @flaxking said in Office 365 SMTP server not advertising StartTLS:

                                        From what I heard from our tech, it sounds like the company's UTM was messing with it.

                                        Which UTM? Hopefully not SOnicwall in this case.

                                        Hopefully it IS SonicWall, so that all these stupid issues can be isolated to one bad vendor rather than sprawling across the industry.

                                        They are not the only one as I can mention many....

                                        1 Reply Last reply Reply Quote 0
                                        • F
                                          flaxking
                                          last edited by

                                          No idea, we don't manage the client's infrastructure

                                          StrongBadS 1 Reply Last reply Reply Quote 0
                                          • StrongBadS
                                            StrongBad @flaxking
                                            last edited by

                                            @flaxking said in Office 365 SMTP server not advertising StartTLS:

                                            No idea, we don't manage the client's infrastructure

                                            Then it was definitely the UTM, no question.

                                            1 Reply Last reply Reply Quote 0
                                            • 1 / 1
                                            • First post
                                              Last post