TLS directive
require-starttls
Require TLS for delivery to a destination.
PowerMTAv4.1 frameworkProduction reference
Production caution: Only enable when the recipient is known to support reliable TLS or mail can remain queued.
Purpose
Require TLS for delivery to a destination. This reference focuses on operational intent, placement, validation, and failure modes rather than presenting a value as universally safe.
Example syntax
require-starttls yesPlacement and scope
The effective scope depends on where the directive is placed: global, source, SMTP user, virtual MTA, pool, or destination domain. Keep related controls together and comment the business purpose of each override.
Verification procedure
- Back up the active configuration and included files.
- Confirm the directive is supported by the installed PowerMTA release.
- Validate every referenced VMTA, pool, file, hostname, IP address, selector, and pattern list.
- Reload safely and watch the main log for parser or runtime errors.
- Send a controlled test and inspect the exact source IP, EHLO, headers, TLS state, and SMTP response.
Common failure modes
- Placing the directive in a scope where it is ignored or overridden.
- Referencing an object that is misspelled or not defined.
- Copying syntax from a different PowerMTA version.
- Using aggressive values without measuring provider acceptance and queue age.