diff --git a/docs/content/docs/guides/mailboxes.mdx b/docs/content/docs/guides/mailboxes.mdx index 971f6939f..a32192cc0 100644 --- a/docs/content/docs/guides/mailboxes.mdx +++ b/docs/content/docs/guides/mailboxes.mdx @@ -53,7 +53,7 @@ Each side also has a **security** setting, which is what decides how the connect | STARTTLS | Connects in the clear, then upgrades in place before anything sensitive is sent | SMTP `587` or `2525`, IMAP `143` | | None | No encryption. Only offered for a mail server on the same machine as the worker | SMTP `1025`, IMAP `1143` | -If port 465 never answers (many hosting networks block outbound 465 while 587 stays open), the worker dials 587 with STARTTLS on the same server alongside it and uses whichever connects first. A connect that succeeds that way is stored with port 587 and STARTTLS, and the mailbox settings show that. A server that refuses the connection or a name that does not resolve is reported as is, because 587 would fail the same way. +If port 465 never answers (many hosting networks block outbound 465 while 587 stays open), the worker dials 587 with STARTTLS on the same server alongside it and uses whichever connects first. A connect that succeeds that way is stored with port 587 and STARTTLS, and the mailbox settings show that. A refusal or a name that does not resolve is an answer from the network, not silence: one that arrives before 587 has been dialled is reported as is, and the fallback is only for a port that never answers. The form picks TLS or STARTTLS from the port as you type, so standard setups need no thought. It never picks **None**, on any port: dropping encryption is always something you ask for. Change the mode yourself when your server is unusual: any port from 1 to 65535 works, so a submission relay on `2525` or IMAP on a custom port is fine as long as the security setting matches what the server actually speaks. diff --git a/internal/client/smtpimap/smtp/submission.go b/internal/client/smtpimap/smtp/submission.go index 84866b0f7..415aefd81 100644 --- a/internal/client/smtpimap/smtp/submission.go +++ b/internal/client/smtpimap/smtp/submission.go @@ -50,8 +50,10 @@ var dialTCP = func(ctx context.Context, local *net.TCPAddr, addr string) (net.Co // as well, in parallel after a head start, and whichever connects first is // used: a port that stays silent is a network in the way, not the server, // and hosts that block outbound 465 mostly leave 587 open. A refused port or -// a name that does not resolve comes back at once and is not retried. When -// nothing connects the error is 465's own. +// a name that does not resolve is an answer: one that arrives before 587 is +// dialled is returned at once; one that arrives later leaves 587 to finish, +// and a 587 that connects is used. When nothing connects the error is 465's +// own. func DialSubmission(ctx context.Context, local *net.TCPAddr, host string, port int, security string) (Dialed, error) { resolved := models.ResolveSMTPSecurity(security, port) if resolved != models.MailSecurityTLS || port != PortSMTPS {