What this check looks at
JoltMx advertises STARTTLS on the connection your test message comes in on, so your sending server gets to choose whether to encrypt. This check records what it did:
- Whether the message was delivered over TLS at all, or in plaintext.
- Which TLS version was negotiated (1.3, 1.2, or a deprecated 1.0/1.1).
This grades outbound encryption from the sender's side. To test whether mail to the domain is encrypted, see the inbound MX STARTTLS check.
Why it matters
Unencrypted mail can be read or tampered with in transit. Gmail and others visibly flag messages that weren't encrypted, and receivers enforcing MTA-STS or DANE will refuse plaintext delivery entirely. Old TLS versions (1.0/1.1) are formally deprecated and increasingly rejected.
How the diagnostic grades it
| Result | Severity | What it means |
|---|---|---|
| TLS 1.3 | Pass | The best available - nothing to do. |
| TLS 1.2 | Pass | Fine today; enable 1.3 when your server supports it. |
| Encrypted (version not reported) | Pass | The connection was encrypted. |
| Sent without TLS | Warning | Plaintext, even though STARTTLS was offered. Enable opportunistic TLS. |
| Legacy TLS version (1.0/1.1) | Warning | Deprecated (RFC 8996) and increasingly refused. Upgrade your TLS stack. |
How to fix it
- Enable opportunistic STARTTLS on outbound mail in your server or sending provider.
- Make sure your TLS stack offers TLS 1.2 and 1.3 and disables 1.0/1.1.