v2.9 · Production runbook

SMTP TLS Handshake Failures

Diagnose certificate, protocol, cipher and interception problems.

Capture

Use timestamps, queue IDs, remote responses, source IP, VMTA, sender domain and message class to establish the failure boundary. Avoid reacting to one isolated delivery attempt.

Checklist

  • Remote MX and resolved IP
  • STARTTLS advertisement
  • TLS protocol and cipher negotiation
  • Certificate chain, hostname and expiry
  • Firewall or proxy interference

Fallback policy

Apply opportunistic fallback only where your security policy permits it. Never silently weaken transport requirements for sensitive traffic.

Operational rule: collect evidence before changing policy, make one controlled change, verify the result, and retain a rollback path.
Search Trushilla Documentation