Hi, we receive mails from $world and forward them to internal exchange server.
Exchange is offering STARTTLS and AUTH root@gate01:~# telnet 192.168.124.5 2525 Trying 192.168.124.5... Connected to 192.168.124.5. Escape character is '^]'. 220 ex01 Microsoft ESMTP MAIL Service ready at Tue, 11 Dec 2018 19:07:13 +0100 ehlo cubewerk.de 250-gate01 Hello [192.168.124.251] 250-SIZE 250-PIPELINING 250-DSN 250-ENHANCEDSTATUSCODES 250-STARTTLS 250-X-ANONYMOUSTLS 250-AUTH NTLM 250-X-EXPS GSSAPI NTLM 250-8BITMIME 250-BINARYMIME 250-CHUNKING 250-XEXCH50 250-XRDST 250 XSHADOWREQUEST Postfix gets ... during address verification. Dec 11 19:27:18 postgate01 postfix/postscreen[583]: DISCONNECT [client]:57636 Dec 11 19:27:18 postgate01 postfix/smtp[574]: 5586D101077: to=< odf...@customer.de>, relay=192.168.124.5[192.168.124.5]:2525, delay=11, delays=1/0.02/10/0, dsn=4.7.3, status=undeliverable (SASL authentication failed; server 192.168.124.5[192.168.124.5] said: 535 5.7.3 Authentication unsuccessful) how can we ignore AUTH and STARTTLS and just go on? telnet shows the dialog i expect: outgoing mails get relayed through smarthost, so this is where all the client tls settings interfere i guess :/