# Sending email failed with SMTPS port 465

**URL:** https://meta.discourse.org/t/sending-email-failed-with-smtps-port-465/65787
**Category:** Self-hosting
**Created:** [7 juli 2017 om 05:07 UTC](https://meta.discourse.org/t/sending-email-failed-with-smtps-port-465/65787 "2017-07-07T05:07:43Z")
**Posts on this page:** 15
**Page:** 1

<div class="post-metadata">

### Author: ![manishramteke](https://avatars.discourse-cdn.com/v4/letter/m/c68b51/32.png) [@manishramteke](https://meta.discourse.org/u/manishramteke)
#### Post date: [7 juli 2017 om 05:07 UTC](https://meta.discourse.org/t/sending-email-failed-with-smtps-port-465/65787/1 "2017-07-07T05:07:43Z")

</div>

Hi Team,

Using email service from godaddy and smtp ssl port 465 in config, but sending mail fails with  
Job exception: end of file reached.

For me 465 works with email client such as thunderbird. What can be done to make email work with discourse on port 465.  
Running SMTP on other port such as 3535 works well. If I go with non secure port will security of my email contents and credentials get compromised?

Regards  
Manish

---

<div class="post-metadata">

### Author: ![mpalmer](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mpalmer/32/45740_2.png) [@mpalmer](https://meta.discourse.org/u/mpalmer)
#### Post date: [7 juli 2017 om 05:19 UTC](https://meta.discourse.org/t/sending-email-failed-with-smtps-port-465/65787/2 "2017-07-07T05:19:37Z")

</div>

This sounds like a problem with your mail provider or the server running Discourse (such as a firewall issue). It is not a problem with Discourse itself.

Also note that port 465 hasn’t been for SMTPS for so long that the IETF has removed its registration as a well-known port. You should use port 25 or 587 with STARTTLS.

---

<div class="post-metadata">

### Author: ![manishramteke](https://avatars.discourse-cdn.com/v4/letter/m/c68b51/32.png) [@manishramteke](https://meta.discourse.org/u/manishramteke)
#### Post date: [7 juli 2017 om 05:46 UTC](https://meta.discourse.org/t/sending-email-failed-with-smtps-port-465/65787/3 "2017-07-07T05:46:06Z")

</div>

Hi Matt,

I am able to telnet port 465 from discourse server and no firewall is configured for now.  
Email providers still supports 465 for secure connection for client which does not support STARTTLS. However that’s not the case here, so I can move to port 25 with STARTTLS on.

Regards  
Manish

---

<div class="post-metadata">

### Author: ![FrankFang](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/frankfang/32/120473_2.png) [@FrankFang](https://meta.discourse.org/u/FrankFang)
#### Post date: [10 december 2017 om 18:52 UTC](https://meta.discourse.org/t/sending-email-failed-with-smtps-port-465/65787/4 "2017-12-10T18:52:50Z")

</div>

Sad to here this.  
My email service provider does not support for port 587.

---

<div class="post-metadata">

### Author: ![mpalmer](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mpalmer/32/45740_2.png) [@mpalmer](https://meta.discourse.org/u/mpalmer)
#### Post date: [10 december 2017 om 22:40 UTC](https://meta.discourse.org/t/sending-email-failed-with-smtps-port-465/65787/5 "2017-12-10T22:40:23Z")

</div>

Your ESP needs to be dragged, kicking and screaming, into the 21st century.

---

<div class="post-metadata">

### Author: ![vitorl](https://avatars.discourse-cdn.com/v4/letter/v/57b2e6/32.png) [@vitorl](https://meta.discourse.org/u/vitorl)
#### Post date: [12 september 2018 om 06:13 UTC](https://meta.discourse.org/t/sending-email-failed-with-smtps-port-465/65787/6 "2018-09-12T06:13:40Z")

</div>

I have been googling for this, to see if I should use port 465 or not.

Can you confirm as of 2018, if the recommended and safe settings is to use port 587 with STARTTLS (DISCOURSE\_SMTP\_ENABLE\_START\_TLS env for dockers) ?

Sendgrid still offers port 465 “for SSL connections” as they say. I was thinking in using it.

---

<div class="post-metadata">

### Author: ![Stephen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/stephen/32/95011_2.png) [@Stephen](https://meta.discourse.org/u/Stephen)
#### Post date: [12 september 2018 om 14:04 UTC](https://meta.discourse.org/t/sending-email-failed-with-smtps-port-465/65787/7 "2018-09-12T14:04:22Z")

</div>

Sendgrid use 587 too. Use 587 with starttls. TLS is effectively the successor to SSL.

---

<div class="post-metadata">

### Author: ![djr013](https://avatars.discourse-cdn.com/v4/letter/d/e68b1a/32.png) [@djr013](https://meta.discourse.org/u/djr013)
#### Post date: [29 september 2019 om 05:47 UTC](https://meta.discourse.org/t/sending-email-failed-with-smtps-port-465/65787/8 "2019-09-29T05:47:12Z")

</div>

> [@mpalmer](#):
>
> Also note that port 465 hasn’t been for SMTPS for so long that the IETF has removed its registration as a well-known port. You should use port 25 or 587 with STARTTLS.

There’s a January 2018 IETF RFC which recommends use of port 465 for “implicit” TLS. A motivation for this is the increasing trend for mandatory encryption, which renders STARTTLS somewhat redundant. [RFC 8314 - Cleartext Considered Obsolete: Use of Transport Layer Security (TLS) for Email Submission and Access](https://tools.ietf.org/html/rfc8314)

---

<div class="post-metadata">

### Author: ![Godmar\_Back](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/godmar_back/32/206246_2.png) [@Godmar\_Back](https://meta.discourse.org/u/Godmar_Back)
#### Post date: [15 januari 2021 om 19:38 UTC](https://meta.discourse.org/t/sending-email-failed-with-smtps-port-465/65787/9 "2021-01-15T19:38:04Z")

</div>

Have there been any updates? My email provider also requires that the client automatically establish a TLS connection on connect on port 465.

How do I tell Discourse to use this option?

To be precise, in `[swaks](https://linux.die.net/man/1/swaks)` this is called --tlsc

```
--tlsc, --tls-on-connect
Initiate a TLS connection immediately on connection. Following common convention, if this option is specified the default port changes from 25 to 465, though this can still be overridden with the --port option.

```

---

<div class="post-metadata">

### Author: ![Godmar\_Back](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/godmar_back/32/206246_2.png) [@Godmar\_Back](https://meta.discourse.org/u/Godmar_Back)
#### Post date: [15 januari 2021 om 20:00 UTC](https://meta.discourse.org/t/sending-email-failed-with-smtps-port-465/65787/10 "2021-01-15T20:00:23Z")

</div>

I think the following is related: a [never completed PR](https://github.com/rails/rails/pull/30483) for Ruby’s action mailer describes how the action mailer needs to be configured. Specifically, the options `tls` and `ssl` need to be added. In Discourse, this could be in production.rb [here](https://github.com/discourse/discourse/blob/master/config/environments/production.rb#L28-L36)

PS: I submitted a [PR with a proposed fix](https://github.com/discourse/discourse/pull/11733) which can also be used as a work-around

---

<div class="post-metadata">

### Author: ![silverdr](https://avatars.discourse-cdn.com/v4/letter/s/e19adc/32.png) [@silverdr](https://meta.discourse.org/u/silverdr)
#### Post date: [2 augustus 2022 om 08:59 UTC](https://meta.discourse.org/t/sending-email-failed-with-smtps-port-465/65787/11 "2022-08-02T08:59:41Z")

</div>

Any practical solutions for sending e-mail over SMTPS on port 465? No, “change your ESP” , “use submission 587” and similar are not solutions to the problem in question 😉

---

<div class="post-metadata">

### Author: ![Jagster](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jagster/32/192154_2.png) [@Jagster](https://meta.discourse.org/u/Jagster)
#### Post date: [2 augustus 2022 om 11:40 UTC](https://meta.discourse.org/t/sending-email-failed-with-smtps-port-465/65787/12 "2022-08-02T11:40:53Z")

</div>

Practical solutions? No… it is quite common policy to force to use 587.

So, what is the issue?

---

<div class="post-metadata">

### Author: ![silverdr](https://avatars.discourse-cdn.com/v4/letter/s/e19adc/32.png) [@silverdr](https://meta.discourse.org/u/silverdr)
#### Post date: [2 augustus 2022 om 16:57 UTC](https://meta.discourse.org/t/sending-email-failed-with-smtps-port-465/65787/13 "2022-08-02T16:57:36Z")

</div>

You mean on the ESP side? Sure, but not on the client (here Discourse server) side. I am still checking and rechecking options so it’s not yet conclusive that it “just doesn’t work” for me but I hope nobody tried to force 587 on the client side here, right?

---

<div class="post-metadata">

### Author: ![vados](https://avatars.discourse-cdn.com/v4/letter/v/f04885/32.png) [@vados](https://meta.discourse.org/u/vados)
#### Post date: [4 december 2022 om 04:58 UTC](https://meta.discourse.org/t/sending-email-failed-with-smtps-port-465/65787/14 "2022-12-04T04:58:12Z")

</div>

**Just wanted to point this out since it seems to have become a common misunderstanding – 587 is not “the future” – implicit TLS over 465 is.**

I was lead to this [revelation by this post](https://linuxguideandhints.com/misc/port465.html)

And upon reading the [actual RFC from 2018](https://www.rfc-editor.org/rfc/rfc8314#section-3.3) it’s clear – it’s not that STARTTLS is the way forward, it’s that SMTPS is _not_ the way forward, and implicit TLS over port 465 (or 587) is what administrators should choose going forward.

Supporting TLS over 465 should not be classed (and likely de-prioritized) as “maintaining backwards compatibility” or any similar notion.

> The STARTTLS mechanism on port 587 is relatively widely deployed due to the situation with port 465 (discussed in Section 7.3. This differs from IMAP and POP services where Implicit TLS is more widely deployed on servers than STARTTLS. **It is desirable to migrate core protocols used by MUA software to Implicit TLS over time** , for consistency as well as for the additional reasons discussed in Appendix A. However, to maximize the use of encryption for submission, it is desirable to support both mechanisms for Message Submission over TLS for a transition period of several years. **As a result, clients and servers SHOULD implement both STARTTLS on port 587 and Implicit TLS on port 465 for this transition period.** Note that there is no significant difference between the security properties of STARTTLS on port 587 and Implicit TLS on port 465 if the implementations are correct and if both the client and the server are configured to require successful negotiation of TLS prior to Message Submission.

The transition is _not_ to `submissions` over 587 via STARTTLS, it’s to `submissions` via implicit TLS on port 465 (as opposed to SMTPS over port 465 which is now deprecated).

---

<div class="post-metadata">

### Author: ![system](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/system/32/443519_2.png) [@system](https://meta.discourse.org/u/system)
#### Post date: [3 januari 2023 om 04:58 UTC](https://meta.discourse.org/t/sending-email-failed-with-smtps-port-465/65787/15 "2023-01-03T04:58:17Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
