You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何修复Mailgun自定义SMTP域名的TLS证书不匹配问题?

Fixing "TLS Negotiation failed, the certificate doesn't match the host" with Mailgun CNAME and Cloudflare

Let's break down why this is happening and walk through the fixes step by step:

Root Cause

Mailgun's SMTP server (smtp.eu.mailgun.org) uses an SSL certificate only valid for its own domain. When you connect via your custom CNAME (smtp.mydomain.com), Gmail's strict TLS validation checks if the presented certificate matches the hostname you're connecting to—and since Mailgun's cert doesn't include smtp.mydomain.com, it throws the mismatch error. Earlier success might have come from less strict validation by other providers, but Gmail enforces this rule strictly now.


Step 1: Check Cloudflare Proxy Status (Critical Quick Fix)

First, rule out a common Cloudflare misconfiguration:

  • Log into your Cloudflare dashboard, navigate to your domain's DNS tab
  • Locate the smtp.mydomain.com CNAME record
  • Ensure the Proxy status is set to DNS only (gray cloud icon), not Proxied (orange cloud).

Cloudflare's proxy doesn't properly handle SMTP TLS termination for custom hostnames—it replaces the certificate with its own, which will never match your SMTP domain. If this was set to proxied, switching it to DNS only might resolve the issue immediately (wait 5-10 minutes for DNS propagation).


Step 2: Configure Mailgun Custom SMTP Hostname (Permanent Solution)

If the proxy status was already DNS only, you need to set up Mailgun to issue a valid certificate for your custom SMTP domain:

  1. Log into your Mailgun dashboard and go to your domain's settings page
  2. Look for the Custom SMTP Hostname option (usually under SMTP settings or Domain Verification)
  3. Enter smtp.mydomain.com as your custom hostname and click "Create"
  4. Mailgun will generate two DNS records to add to Cloudflare:
    • A CNAME record pointing smtp.mydomain.com to a Mailgun-managed target (e.g., smtp.mydomain.com.mg.eu.mailgun.org)
    • A TXT record for domain validation (e.g., smtp.mydomain.com with value v=mailgun; id=abc123)
  5. Add these records to Cloudflare (keep them set to DNS only) and wait 15-60 minutes for DNS propagation
  6. Once Mailgun verifies the records, it will issue an SSL certificate for smtp.mydomain.com. Now when you connect via this hostname, the TLS certificate will match, and Gmail will accept the connection.

Verify the Fix

To confirm everything works, run this command in your terminal to check the TLS handshake:

openssl s_client -connect smtp.mydomain.com:465

Look for Verify return code: 0 (ok) in the output—this means the certificate matches the hostname correctly.

内容的提问来源于stack exchange,提问作者GSite

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.07 09:42:32