FortiMail
FortiMail provides advanced, multi-layer protection against the full spectrum of email-borne threats
Sunil_Panchal
Article Id 421027
Description This article describes how to fix the STARTTLS issue for older devices/applications to relay email.
Scope FortiMail.
Solution

A situation arises when FortiMail stops relaying email from older devices/applications due to a STARTTLS issue.

 

Application_to_relay.png

 

Old Application/printer does not support STARTTLS, but it used to work and relay email before. But due to a change in FortiMail, email relay from these devices stops working.

 

In such a case, the logs on FortiMail should be checked first to identify the error being generated and the policy associated with it. .

 

from=<test@demolab.local>, size=0, class=0, nrcpts=1, proto=ESMTP, daemon=SMTP_MTA, relay=[172.26.61.6]

Milter: to=<app@external.local>, reject=421 4.7.0 STARTTLS is mandatory

TLS is mandatory

 

Application_to_relay_logs.png

 

The screenshot shows that policy 1:1:0 SYSTEM was used for relaying. The first step is to review ACL 1.

 

Application_to_relay_ACL_should_have_TLS.png

 

The ACL is used to enforce STARTTLS to outbound email for Internal-User/Source_IP address. This STARTTLS enforcement needs to be disabled to allow email from those old applications/printers.

 

Application_to_relay_ACL_should_have.png  

TLS profile for such a device should be NONE.