> "TLS-only" might work if you use "stream" rather than "mail", so that > nginx is the TLS-termination of an otherwise-opaque stream of traffic. Thanks for the hint. I think I can omit starttls support and use only TLS Posted at Nginx Forum: https://forum.nginx.org/read.php?2,289589,289617#msg-289617