1

Topic: Can't use mail clients

==== REQUIRED BASIC INFO OF YOUR IREDMAIL SERVER ====
- iRedMail version (check /etc/iredmail-release): 1.4.0 MARIADB edition
- Deployed with iRedMail Easy or the downloadable installer? With the downloadable installer.
- Linux/BSD distribution name and version: Debian 10
- Store mail accounts in which backend (LDAP/MySQL/PGSQL): MySQL
- Web server (Apache or Nginx): Nginx
- Manage mail accounts with iRedAdmin-Pro? No
- [IMPORTANT] Related original log or error message is required if you're experiencing an issue.
====
Hi everyone, first time here!
I need a bit of help with my iRedMail server. I was migrated a entire mail server from bluehost to my own iredMail server and was an amazing process, webmail is so fast and very nice to use, but now, i have a big issue that i can't solve:
I have my iRedMail server behind a proxy web server for access from internet to him at port 80 and 443 for webmail, all of this is working correctly but i can't make client mail works (like Thunderbird, Outlook, Gmail, etc). My dns are hosted into Cloudflare with an bussiness plan and i think everything is ok except ssl for the smtp. When i connect my accounts into Thunderbird it connect with imap and pop but i was prompted by and certificate issue, so i think the ssl certificates into my server aren't working.
The question is: How i can see what ssl certificate am i using into that server? When i was prompted in Thunderbird i saw that the certificate is for cloudflare so it's good, but it's not secure.
Any ideas?

Important info:
hostname: mail.XXX.com
domain: XXX.com

----

Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.

2

Re: Can't use mail clients

Your ssl cert must support the server hostname used in Thunderbird.

3

Re: Can't use mail clients

Yes, it's supported by cloudflare with the FQDN

ZhangHuangbin wrote:

Your ssl cert must support the server hostname used in Thunderbird.

4

Re: Can't use mail clients

You can validate the SSL cert with openssl command line or a few websites.

https://www.ssllabs.com/ssltest is a very comprehensive test of SSL and TLS configuration of webservers including available ciphers.

If everything looks good there you can test SMTP connections over TLS with a tool like wormly.

https://www.wormly.com/test-smtp-server/

They'll indicate what's the issue and we can help go from there.

5

Re: Can't use mail clients

Just asking, but did you read and follow this: https://docs.iredmail.org/use.a.bought. … icate.html ?

PS. Also upgrade iRedMail to the latest version, including all components to prevent being hacked because of out-of-date vulnerable components. Follow this: https://docs.iredmail.org/iredmail.releases.html

6

Re: Can't use mail clients

[SOLVED] By the way, i have cloudflare for my domains but i don't use the ssl of them for my mail server. I followed the guide for iredmail letsencrypt and that was it.
For the email clients, i don't see the iptables for dovecot, so my ip address was banned and that was the problem.
Thank you to all of you.