如何修复Mailgun自定义SMTP域名的TLS证书不匹配问题?
Let's break down why this is happening and walk through the fixes step by step:
Root Cause
Mailgun's SMTP server (smtp.eu.mailgun.org) uses an SSL certificate only valid for its own domain. When you connect via your custom CNAME (smtp.mydomain.com), Gmail's strict TLS validation checks if the presented certificate matches the hostname you're connecting to—and since Mailgun's cert doesn't include smtp.mydomain.com, it throws the mismatch error. Earlier success might have come from less strict validation by other providers, but Gmail enforces this rule strictly now.
Step 1: Check Cloudflare Proxy Status (Critical Quick Fix)
First, rule out a common Cloudflare misconfiguration:
- Log into your Cloudflare dashboard, navigate to your domain's DNS tab
- Locate the
smtp.mydomain.comCNAME record - Ensure the Proxy status is set to DNS only (gray cloud icon), not Proxied (orange cloud).
Cloudflare's proxy doesn't properly handle SMTP TLS termination for custom hostnames—it replaces the certificate with its own, which will never match your SMTP domain. If this was set to proxied, switching it to DNS only might resolve the issue immediately (wait 5-10 minutes for DNS propagation).
Step 2: Configure Mailgun Custom SMTP Hostname (Permanent Solution)
If the proxy status was already DNS only, you need to set up Mailgun to issue a valid certificate for your custom SMTP domain:
- Log into your Mailgun dashboard and go to your domain's settings page
- Look for the Custom SMTP Hostname option (usually under SMTP settings or Domain Verification)
- Enter
smtp.mydomain.comas your custom hostname and click "Create" - Mailgun will generate two DNS records to add to Cloudflare:
- A CNAME record pointing
smtp.mydomain.comto a Mailgun-managed target (e.g.,smtp.mydomain.com.mg.eu.mailgun.org) - A TXT record for domain validation (e.g.,
smtp.mydomain.comwith valuev=mailgun; id=abc123)
- A CNAME record pointing
- Add these records to Cloudflare (keep them set to DNS only) and wait 15-60 minutes for DNS propagation
- Once Mailgun verifies the records, it will issue an SSL certificate for
smtp.mydomain.com. Now when you connect via this hostname, the TLS certificate will match, and Gmail will accept the connection.
Verify the Fix
To confirm everything works, run this command in your terminal to check the TLS handshake:
openssl s_client -connect smtp.mydomain.com:465
Look for Verify return code: 0 (ok) in the output—this means the certificate matches the hostname correctly.
内容的提问来源于stack exchange,提问作者GSite

