How STARTTLS works
SMTP, the protocol that moves email, began as plain text. STARTTLS was added so servers could turn on encryption inside the same connection, on the same port, without breaking older servers.1
- The sending server connects and says hello with the EHLO command.
- The receiving server lists what it supports. If the list includes STARTTLS, encryption is on offer.
- The sender replies with STARTTLS and the receiver answers that it is ready.
- The two run a TLS handshake. From here on, everything on the connection is encrypted.
- The sender says hello again and delivers the message inside the encrypted connection.
STARTTLS and implicit TLS
There are two ways to put TLS on a mail connection. STARTTLS starts in plain text and upgrades. Implicit TLS, the setting many mail apps label SSL/TLS, is encrypted from the very start.
| Port | Used for | How TLS starts |
|---|---|---|
| 25 | Mail moving from one provider’s server to another | STARTTLS, if both servers offer it |
| 587 | A mail app handing a new message to its provider | STARTTLS |
| 465 | A mail app handing a new message to its provider | Implicit TLS, encrypted from the start |
For connections between a mail app and its provider, the IETF now recommends implicit TLS over STARTTLS.2 Between providers, on port 25, STARTTLS remains the way encryption starts.
Why it matters, and its weak spot
STARTTLS is the reason most email is no longer readable by every network it crosses. Its weakness is in the name “opportunistic.” The standard says a public mail server must not require STARTTLS to accept mail, and it warns that an attacker in the path can delete the STARTTLS line from the server’s reply.1 The sender then believes encryption isn’t available and sends in plain text.
The fix is a policy on top. MTA-STS, and the DNS-based alternative DANE, let a domain declare that mail for it must always travel over TLS with a valid certificate.3
Where you’ll see STARTTLS
- In mail app settings, as a choice next to SSL/TLS when you enter server details by hand.
- In email headers. A Received line that says ESMTPS, or names a TLS version, shows that hop was encrypted.
- Beyond email. The same upgrade idea exists in other protocols, such as IMAP, POP3 and LDAP.
STARTTLS and Secria
In transit, Secria mail travels over TLS, and our domains publish an MTA-STS policy in enforce mode with TLS reporting, so servers that support it don’t fall back to plain text when delivering to Secria. Once a message arrives, it is stored with zero-access encryption.
Related terms
Sources
- IETF, RFC 3207: SMTP Service Extension for Secure SMTP over Transport Layer Security (February 2002).
- IETF, RFC 8314: Cleartext Considered Obsolete: Use of Transport Layer Security (TLS) for Email Submission and Access (January 2018).
- IETF, RFC 8461: SMTP MTA Strict Transport Security (MTA-STS) (September 2018).
Checked October 2026. Secria’s own records are public in DNS and were read on 11 October 2026. Other Secria facts are from our Mail and VPN pages.
Questions about STARTTLS
What is the difference between STARTTLS and TLS?
TLS is the encryption protocol. STARTTLS is a command that switches a plain connection over to TLS. After the switch, the protection is the same TLS in both cases.
Is STARTTLS secure?
Once the connection is upgraded, it is protected by TLS. The weak point is the start: the offer to upgrade travels in plain text and can be removed by someone in the path. Policies such as MTA-STS close that gap by making TLS mandatory.
Should I choose STARTTLS or SSL/TLS in my mail app?
Use whichever your provider lists for the port. SSL/TLS, also called implicit TLS, usually goes with port 465 and is encrypted from the start. STARTTLS usually goes with port 587. Current IETF guidance prefers implicit TLS where the provider offers it.
Which port does STARTTLS use?
STARTTLS isn’t tied to one port. For email it is used on port 25 between providers and on port 587 between a mail app and its provider.