Capture
Use timestamps, queue IDs, remote responses, source IP, VMTA, sender domain and message class to establish the failure boundary. Avoid reacting to one isolated delivery attempt.
Checklist
- Remote MX and resolved IP
- STARTTLS advertisement
- TLS protocol and cipher negotiation
- Certificate chain, hostname and expiry
- Firewall or proxy interference
Fallback policy
Apply opportunistic fallback only where your security policy permits it. Never silently weaken transport requirements for sensitive traffic.
Operational rule: collect evidence before changing policy, make one controlled change, verify the result, and retain a rollback path.