Skip to main content
This forum is closed to new posts and responses. Individual names altered for privacy purposes. The information contained in this website is provided for informational purposes only and should not be construed as a forum for customer support requests. Any customer support requests should be directed to the official HCL customer support channels below:

HCL Software Customer Support Portal for U.S. Federal Government clients
HCL Software Customer Support Portal

HCL Notes/Domino 8.5 Forum (includes Notes Traveler)

HCL Notes/Domino 8.5 Forum (includes Notes Traveler)

Previous Next

For those still following

Alright, after more testing, I've determined the issue is with X.com's highest priority MX relay (seluimxhigh.X.com). My domino server tries to connect to seluimxhigh.X.com, but doesn't connect because of an ssl handshake error. The error indicates a bad peer certificate. I've gone over my servers certificate with a fine toothed comb and can find no problems with it. I started to look into X.com's side of things, and it really looks like the problem is on there end.

The certs on all of their relays are self signed, which seems like a bad setup, but isn't what is causing the problem. I needed to be able to test a connection to their relays from a source other than my own. I used CheckTLS.com, which just uses a perl script. You can see in the screenshot below that it fails to connect to seluimxhigh.X.com as well. It manages to connect to all of their other relays, which I can confirm because I am able to telnet to port 25 on them from my server. Since according to X.com, I'm the only domain which can't send mail to them, and because checktls.com also can't connect to seluimxhigh.X.com, I would guess that other mail servers simply send to one of their 5 other relays.

Assuming this is all correct (I could be wrong), then it makes me wonder why my server doesn't just send to one of the other relays after the highest priority one fails.

CheckTLS status for X.com screenshot
http://i.imgur.com/X9iY8.jpg


Feedback response number WEBB8WCNZQ created by ~John Ellusonader on 07/19/2012

Emails not delivered to single doma... (~John Ellusonad... 13.Jul.12)
. . How do these log entries compare to... (~Mario Asaresab... 16.Jul.12)
. . . . Successful comparison (~John Ellusonad... 16.Jul.12)
. . Bounce back finally received (~John Ellusonad... 16.Jul.12)
. . . . Flush your DNS Cache on the Domino ... (~Mario Asaresab... 16.Jul.12)
. . . . . . More info (~John Ellusonad... 17.Jul.12)
. . . . . . . . For those still following (~John Ellusonad... 19.Jul.12)
. . . . . . . . . . More MX Relay Info (~John Ellusonad... 19.Jul.12)
. . . . . . . . . . . . Flushed dns cache again (~John Ellusonad... 19.Jul.12)
. . . . . . . . . . . . . . Did you find a cause? (~Tate Desnuskia... 5.Sep.12)
. . We also encountered this problem. (~Tanita Nonjumi... 14.Jun.13)
. . . . work-around (~Fred Desluberg... 9.Dec.13)
. . . . . . Worked a treat (~Samuel Renuthe... 7.Oct.14)
. . . . . . Thank you, thank you! (~Lily Bretoomar... 13.Nov.14)
. . . . TLS issue just started with us on 1... (~Bella Kiazen 14.Nov.14)




Printer-friendly

Search this forum

Member Tools


RSS Feeds

 RSS feedsRSS
All forum posts RSS
All main topics RSS