On Tue, Nov 11, 2014 at 01:49:19PM -0500, Wietse Venema wrote: > > > http://www.postfix.org/postconf.5.html#smtp_delivery_status_filter > > > > Yes, this "works", but it is very much not recommended. When > > receiving systems botch their certificate chains (expired, incomplete > > chain, ...) and mail is delayed, they should generally be motivated > > to fix the problem quickly. > > I agree that screwing up with certificates is easy enough, but this > is a case where the MX server does not announce STARTTLS support.
For the record, I am not disagreeing with your response, just trying to encourage the OP to consider alternatives. Even a missing STARTTLS can be a transient operational error. -- Viktor.