You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ASP.NET Core应用通过MailKit连接MailEnable SMTP服务器遇SSL证书错误

问题:ASP.NET Core应用通过MailEnable发送邮件时SSL证书验证失败

环境信息

  • 操作系统:Windows Server 2012 R2
  • 邮件服务:MailEnable Standard Version 10.34
  • Web服务:IIS托管多个ASP.NET Core应用
  • 控制面板:Plesk Obsidian 18.0.40
  • 证书配置:
    • IIS中各Web应用使用2个月前颁发的SSL证书
    • Plesk中每个网站配置Let's Encrypt证书,对应关系:
      Lets Encrypt mydomain.com  ---> Secures webmail
      www.mydomain.com           ---> Secures mail
      

故障现象

某Web应用突然无法发送邮件,调用SmtpClient的Connect方法时抛出异常:

An error occurred while attempting to establish an SSL or TLS connection. The host name did not match the name given in the server's SSL certificate.
内部异常:The remote certificate is invalid according to the validation procedure.

相关代码片段:

using (MailKit.Net.Smtp.SmtpClient smtp = new MailKit.Net.Smtp.SmtpClient()) 
{
    try
    {
        smtp.Connect("xxx.xxx.xxx.xxx", 587, false);
        ...
    }
    catch (Exception ex) { ... }
}

已尝试操作:更新MailEnable服务器节点属性→SSL标签中的默认SSL证书,问题仍存在。


问题分析与排查方向

原因解析

异常核心是SSL证书主机名不匹配:

  1. 代码直接使用服务器IP连接SMTP服务,但MailEnable返回的SSL证书未将该IP作为主题备用名称(SAN)或证书主体名;
  2. Plesk配置的Let's Encrypt证书仅针对域名(mydomain.com/www.mydomain.com),而非服务器IP,IP连接触发证书验证逻辑判定主机名不匹配;
  3. 虽更新了MailEnable默认证书,但可能存在证书本身不含IP、SMTP服务未加载新证书、Plesk自动覆盖MailEnable证书配置等情况。

排查方向

1. 检查MailEnable SMTP服务证书配置

  • 打开MailEnable管理控制台,进入Servers → Localhost → Services and Connectors → SMTP,右键SMTP服务选择「Properties」;
  • 切换到「SSL」标签,确认选中的证书是否包含服务器IP作为SAN,或证书主体名为该IP;
  • 重启MailEnable SMTP服务,确保配置生效;
  • 用openssl s_client -connect xxx.xxx.xxx.xxx:587 -starttls smtp命令(需安装OpenSSL)查看返回的证书信息,确认Subject和Subject Alternative Name字段是否包含连接用IP。

2. 排查Plesk与MailEnable的证书关联

  • 登录Plesk,进入对应域名的「SSL/TLS Certificates」页面,确认绑定到「mail」的证书(www.mydomain.com)是否被MailEnable SMTP服务使用;
  • 检查Plesk是否自动覆盖MailEnable证书配置:Plesk与MailEnable的集成可能自动同步证书,手动修改后可能被再次覆盖,需在Plesk中确认MailEnable的证书设置;
  • 查看Plesk日志(%plesk_dir%\var\logs\),确认近期是否有证书自动更新或配置同步操作,导致MailEnable证书被替换。

3. 调整代码连接方式(临时验证)

  • 修改代码使用域名而非IP连接,例如smtp.Connect("www.mydomain.com", 587, false),因为Plesk配置的证书对应www.mydomain.com用于邮件服务;
  • 若必须用IP连接,可临时跳过证书验证(仅用于测试,生产环境禁用):
    smtp.ServerCertificateValidationCallback = (sender, certificate, chain, sslPolicyErrors) => true;
    
    若跳过验证后可正常发邮件,即可确认是证书主机名不匹配导致的问题。

4. 检查IIS证书对MailEnable的影响

  • 确认IIS Web应用证书与MailEnable使用的证书是否冲突:虽IIS和MailEnable是独立服务,但证书存储中同名或冲突的证书可能导致MailEnable加载错误证书;
  • 打开「证书管理器」(certlm.msc),检查「个人」存储中的证书,确认MailEnable配置的证书是否有效、未过期,且包含正确的主机名/IP。

内容的提问来源于stack exchange,提问作者dpant

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.07 22:45:40