TLS in transit check

This is the one check that grades the actual connection your message arrived on: did your server use encryption, and which TLS version did it negotiate?

What this check looks at

JoltMx advertises STARTTLS on the connection your test message comes in on, so your sending server gets to choose whether to encrypt. This check records what it did:

  • Whether the message was delivered over TLS at all, or in plaintext.
  • Which TLS version was negotiated (1.3, 1.2, or a deprecated 1.0/1.1).

This grades outbound encryption from the sender's side. To test whether mail to the domain is encrypted, see the inbound MX STARTTLS check.

Why it matters

Unencrypted mail can be read or tampered with in transit. Gmail and others visibly flag messages that weren't encrypted, and receivers enforcing MTA-STS or DANE will refuse plaintext delivery entirely. Old TLS versions (1.0/1.1) are formally deprecated and increasingly rejected.

How the diagnostic grades it

ResultSeverityWhat it means
TLS 1.3PassThe best available - nothing to do.
TLS 1.2PassFine today; enable 1.3 when your server supports it.
Encrypted (version not reported)PassThe connection was encrypted.
Sent without TLSWarningPlaintext, even though STARTTLS was offered. Enable opportunistic TLS.
Legacy TLS version (1.0/1.1)WarningDeprecated (RFC 8996) and increasingly refused. Upgrade your TLS stack.

How to fix it

  • Enable opportunistic STARTTLS on outbound mail in your server or sending provider.
  • Make sure your TLS stack offers TLS 1.2 and 1.3 and disables 1.0/1.1.

Related checks

Inbound MX STARTTLS · MTA-STS · TLS-RPT

Free during beta

Start routing mail in minutes.

Point your MX records at JoltMx. Add a domain. Create your first rule. Done.

No credit card required  ·  Free tier stays free