ASP.NET Core应用通过MailKit连接MailEnable SMTP服务器遇SSL证书错误
问题:ASP.NET Core应用通过MailEnable发送邮件时SSL证书验证失败
环境信息
- 操作系统:Windows Server 2012 R2
- 邮件服务:MailEnable Standard Version 10.34
- Web服务:IIS托管多个ASP.NET Core应用
- 控制面板:Plesk Obsidian 18.0.40
- 证书配置:
- IIS中各Web应用使用2个月前颁发的SSL证书
- Plesk中每个网站配置Let's Encrypt证书,对应关系:
Lets Encrypt mydomain.com ---> Secures webmail www.mydomain.com ---> Secures mail
故障现象
某Web应用突然无法发送邮件,调用SmtpClient的Connect方法时抛出异常:
An error occurred while attempting to establish an SSL or TLS connection. The host name did not match the name given in the server's SSL certificate.
内部异常:The remote certificate is invalid according to the validation procedure.
相关代码片段:
using (MailKit.Net.Smtp.SmtpClient smtp = new MailKit.Net.Smtp.SmtpClient()) { try { smtp.Connect("xxx.xxx.xxx.xxx", 587, false); ... } catch (Exception ex) { ... } }
已尝试操作:更新MailEnable服务器节点属性→SSL标签中的默认SSL证书,问题仍存在。
问题分析与排查方向
原因解析
异常核心是SSL证书主机名不匹配:
- 代码直接使用服务器IP连接SMTP服务,但MailEnable返回的SSL证书未将该IP作为主题备用名称(SAN)或证书主体名;
- Plesk配置的Let's Encrypt证书仅针对域名(
mydomain.com/www.mydomain.com),而非服务器IP,IP连接触发证书验证逻辑判定主机名不匹配; - 虽更新了MailEnable默认证书,但可能存在证书本身不含IP、SMTP服务未加载新证书、Plesk自动覆盖MailEnable证书配置等情况。
排查方向
1. 检查MailEnable SMTP服务证书配置
- 打开MailEnable管理控制台,进入Servers → Localhost → Services and Connectors → SMTP,右键SMTP服务选择「Properties」;
- 切换到「SSL」标签,确认选中的证书是否包含服务器IP作为SAN,或证书主体名为该IP;
- 重启MailEnable SMTP服务,确保配置生效;
- 用
openssl s_client -connect xxx.xxx.xxx.xxx:587 -starttls smtp命令(需安装OpenSSL)查看返回的证书信息,确认Subject和Subject Alternative Name字段是否包含连接用IP。
2. 排查Plesk与MailEnable的证书关联
- 登录Plesk,进入对应域名的「SSL/TLS Certificates」页面,确认绑定到「mail」的证书(
www.mydomain.com)是否被MailEnable SMTP服务使用; - 检查Plesk是否自动覆盖MailEnable证书配置:Plesk与MailEnable的集成可能自动同步证书,手动修改后可能被再次覆盖,需在Plesk中确认MailEnable的证书设置;
- 查看Plesk日志(
%plesk_dir%\var\logs\),确认近期是否有证书自动更新或配置同步操作,导致MailEnable证书被替换。
3. 调整代码连接方式(临时验证)
- 修改代码使用域名而非IP连接,例如
smtp.Connect("www.mydomain.com", 587, false),因为Plesk配置的证书对应www.mydomain.com用于邮件服务; - 若必须用IP连接,可临时跳过证书验证(仅用于测试,生产环境禁用):
若跳过验证后可正常发邮件,即可确认是证书主机名不匹配导致的问题。smtp.ServerCertificateValidationCallback = (sender, certificate, chain, sslPolicyErrors) => true;
4. 检查IIS证书对MailEnable的影响
- 确认IIS Web应用证书与MailEnable使用的证书是否冲突:虽IIS和MailEnable是独立服务,但证书存储中同名或冲突的证书可能导致MailEnable加载错误证书;
- 打开「证书管理器」(certlm.msc),检查「个人」存储中的证书,确认MailEnable配置的证书是否有效、未过期,且包含正确的主机名/IP。
内容的提问来源于stack exchange,提问作者dpant
相关产品推荐
相关产品推荐

