Deferred: 403 4.7.0 encryption too weak 0 less than 128
Problem reported by terry fairbrother - Today at 2:55 AM
Submitted
I have a bank that is trying to email a user but the bank is getting a bounced email...

    **********************************************
    **      THIS IS A WARNING MESSAGE ONLY      **
    **  YOU DO NOT NEED TO RESEND YOUR MESSAGE  **
    **********************************************
 
The original message was received at Mon, 2 Mar 2026 09:13:30 GMT
from m0357617.ppops.net [127.0.0.1]
 
   ----- Transcript of session follows -----
403 4.7.0 encryption too weak 0 less than 128
<some.user@ourdomain.com>... Deferred: 403 4.7.0 encryption too weak 0 less than 128
Warning: message still undelivered after 4 hours
Will keep trying until message is 5 days old


Having googled it, it comes back as weak TLS, however I don't believe a bank would still be running TLS 1.0. I can see in the SMTP logs that they are being accepted, but I can't figure out what the issue is. Cert is up to date. I have enabled 465 & 587 too as I only wanted 25 / 443 enabled

Any ideas? I have suggested the sender sends the bounce to the banks support team. I suspect it's their end rather than SM

Thanks
Terry

Reply to Thread

Enter the verification text