Jake Vickers wrote:
Are there good reasons to NOT use TLS on port 25? (ie: in master.cf: -o
smtpd_use_tls=no)
no.
but it is a good idea to enable the submission port and start
"migrating" MUAs to use it.
Curious as to if it breaks things for certain clients or something.
if the client isn't configured to use TLS, it will ignore it.
the main problem is to get the MUA to accept the server certificate.
This mostly means that the name in the certificate should match the name
of the server as configured in the MUA.