You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Python通过Proton Bridge连接ProtonMail遇SSL版本错误求助

问题

尝试用Python的imaplib库通过Proton Bridge登录ProtonMail账户,目标是统计未读邮件数量。在Pop!_OS 22.04 LTS(内核版本5.19.0-76051900-generic)运行代码时,出现错误:

ssl.SSLError: [SSL: WRONG_VERSION_NUMBER] wrong version number (_ssl.c:997)

使用的代码如下:

#!/usr/bin/python3 
import imaplib
import ssl

usern="username"
passw="password"
bridge_certificate="cert.pem"


sslctx = ssl.SSLContext(ssl.PROTOCOL_TLS_CLIENT)
sslctx.options &= ~ssl.OP_NO_SSLv3
sslctx.load_verify_locations(cafile=bridge_certificate)
sslctx.verify_mode = ssl.CERT_OPTIONAL
sslctx.check_hostname = False

count = 0
imap = imaplib.IMAP4_SSL("localhost", 1143, ssl_context=sslctx)
imap.login(usern, passw)
imap.select('INBOX')
status, response = imap.search(None, '(UNSEEN)')
if status == 'OK':
    for num in response[0].split():
        count=count+1
print(count)
imap.close()
imap.logout()
错误原因分析

这个错误核心是SSL版本不匹配,具体原因有两点:

  1. Proton Bridge的1143端口是明文IMAP端口,不需要直接用SSL/TLS连接,你用IMAP4_SSL去连接这个端口相当于给明文连接套了SSL层,导致协议版本不兼容。
  2. 代码中手动开启了已废弃的SSLv3协议,现代服务包括Proton Bridge都不再支持该协议,进一步加剧了版本不匹配问题。
解决方法

方法一:明文连接后升级TLS(推荐)

Proton Bridge的1143端口为明文端口,应先建立普通IMAP连接,再通过starttls升级为加密连接:

#!/usr/bin/python3 
import imaplib
import ssl

usern="username"
passw="password"
bridge_certificate="cert.pem"

sslctx = ssl.SSLContext(ssl.PROTOCOL_TLS_CLIENT)
sslctx.load_verify_locations(cafile=bridge_certificate)
sslctx.verify_mode = ssl.CERT_REQUIRED
sslctx.check_hostname = True

count = 0
# 建立明文IMAP连接
imap = imaplib.IMAP4("localhost", 1143)
# 升级到TLS加密
imap.starttls(ssl_context=sslctx)
imap.login(usern, passw)
imap.select('INBOX')
status, response = imap.search(None, '(UNSEEN)')
if status == 'OK':
    count = len(response[0].split()) if response[0] else 0
print(count)
imap.close()
imap.logout()

方法二:直接连接SSL端口

Proton Bridge默认提供993作为IMAP SSL端口,可直接用IMAP4_SSL连接:

#!/usr/bin/python3 
import imaplib
import ssl

usern="username"
passw="password"
bridge_certificate="cert.pem"

sslctx = ssl.SSLContext(ssl.PROTOCOL_TLS_CLIENT)
sslctx.load_verify_locations(cafile=bridge_certificate)
sslctx.verify_mode = ssl.CERT_REQUIRED
sslctx.check_hostname = True

count = 0
# 连接SSL端口993
imap = imaplib.IMAP4_SSL("localhost", 993, ssl_context=sslctx)
imap.login(usern, passw)
imap.select('INBOX')
status, response = imap.search(None, '(UNSEEN)')
if status == 'OK':
    count = len(response[0].split()) if response[0] else 0
print(count)
imap.close()
imap.logout()

额外优化说明

  • 移除了启用SSLv3的代码,避免使用不安全协议
  • 将证书验证模式改为ssl.CERT_REQUIRED,保证连接安全性
  • 简化未读邮件计数逻辑,用len()统计更高效

内容的提问来源于stack exchange,提问作者atammayata

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.26 16:43:09