From 256913b923ce5d0edee1edecdb0ab38aed15ce37 Mon Sep 17 00:00:00 2001 From: RonniSkansing Date: Sat, 26 Sep 2026 20:53:54 +0200 Subject: [PATCH] fix smtp should use implicit tls on 465 insteadof starttls Signed-off-by: RonniSkansing --- backend/service/campaign.go | 13 +++++++++++++ backend/service/email.go | 6 ++++++ backend/service/smtpConfiguration.go | 12 ++++++++++++ 3 files changed, 31 insertions(+) diff --git a/backend/service/campaign.go b/backend/service/campaign.go index 6410c286..a3a01425 100644 --- a/backend/service/campaign.go +++ b/backend/service/campaign.go @@ -3112,6 +3112,12 @@ func (c *Campaign) sendCampaignMessages( }, ), } + // port 465 speaks implicit TLS (SMTPS): the connection is wrapped in + // TLS on connect instead of being upgraded later via STARTTLS. go-mail + // ignores the TLS policy while SSL is on. + if smtpPort.Int() == 465 { + emailOptions = append(emailOptions, mail.WithSSL()) + } // use a custom HELO/EHLO hostname when set, otherwise go-mail // falls back to the machine hostname if helo, err := smtpConfig.Helo.Get(); err == nil { @@ -5563,6 +5569,13 @@ func (c *Campaign) sendSingleEmailSMTP( ), } + // port 465 speaks implicit TLS (SMTPS): the connection is wrapped in + // TLS on connect instead of being upgraded later via STARTTLS. go-mail + // ignores the TLS policy while SSL is on. + if smtpPort.Int() == 465 { + emailOptions = append(emailOptions, mail.WithSSL()) + } + // use a custom HELO/EHLO hostname when set, otherwise go-mail // falls back to the machine hostname if helo, err := smtpConfig.Helo.Get(); err == nil { diff --git a/backend/service/email.go b/backend/service/email.go index 86f6fe40..8a23fdb4 100644 --- a/backend/service/email.go +++ b/backend/service/email.go @@ -532,6 +532,12 @@ func (m *Email) SendTestEmail( }, ), } + // port 465 speaks implicit TLS (SMTPS): the connection is wrapped in + // TLS on connect instead of being upgraded later via STARTTLS. go-mail + // ignores the TLS policy while SSL is on. + if smtpPort.Int() == 465 { + emailOptions = append(emailOptions, mail.WithSSL()) + } // use a custom HELO/EHLO hostname when set, otherwise go-mail // falls back to the machine hostname if helo, err := smtp.Helo.Get(); err == nil { diff --git a/backend/service/smtpConfiguration.go b/backend/service/smtpConfiguration.go index f35f9175..dfbb447c 100644 --- a/backend/service/smtpConfiguration.go +++ b/backend/service/smtpConfiguration.go @@ -244,6 +244,12 @@ func (s *SMTPConfiguration) SendTestEmail( }, ), } + // port 465 speaks implicit TLS (SMTPS): the connection is wrapped in + // TLS on connect instead of being upgraded later via STARTTLS. go-mail + // ignores the TLS policy while SSL is on. + if smtpPort.Int() == 465 { + emailOptions = append(emailOptions, mail.WithSSL()) + } // use a custom HELO/EHLO hostname when set, otherwise go-mail // falls back to the machine hostname if helo, err := smtpConfig.Helo.Get(); err == nil { @@ -668,6 +674,12 @@ func (s *SMTPConfiguration) SendMessages( }, ), } + // port 465 speaks implicit TLS (SMTPS): the connection is wrapped in + // TLS on connect instead of being upgraded later via STARTTLS. go-mail + // ignores the TLS policy while SSL is on. + if smtpPort.Int() == 465 { + emailOptions = append(emailOptions, mail.WithSSL()) + } // use a custom HELO/EHLO hostname when set, otherwise go-mail // falls back to the machine hostname if helo, err := smtpConfig.Helo.Get(); err == nil {