Verizon FiOS outbound mail TLS problem - Superpages people here?

Blake Hudson blake at ispn.net
Thu Jun 4 16:46:35 UTC 2015


I have no relation, but as a mail server operator I can say that I 
wouldn't be surprised if this is actually a TLS version mismatch or 
intolerance problem. I would suggest ensuring that both ends support TLS 
1.0, 1.1, and 1.2 and use version tolerant TLS implementations. Next on 
the short list would be not having compatible cyphers between the two 
servers.

Either way, since the error was a 403 error, the expected behavior would 
be to queue and retry in plain text; Sounds like a broken MTA 
implementation or misconfiguration if the sending servers do not revert 
to plain text.

--Blake

Jay Ashworth wrote on 6/4/2015 11:15 AM:
> Anyone on the list who does outbound delivery for Verizon (which I think
> is actually Superpages)?  A client has smart-hosted outbounds to *one*
> of his customers bouncing suddenly with
>
>    Deferred: 403 4.7.0 TLS handshake failed.
>
> *My* inclination is to think that a cert expired somewhere, but his non-tech
> contact there tells him that the tech people think things are ok.
>
> I'm trying to get a mailer log fragment from them.
>
> Cheers,
> -- jra
>




More information about the NANOG mailing list