SSL/TLS = encryption negotiation is required to even connect.
StartTLS = insecure connect first, then upgrade.
-- in a nutshell.
an example would be:
StartTLS can be enabled on port 25 and remote servers can upgrade their connection security if they want it - there are many out there that still don't.
SSL/TLS requires a secure connection before anything else - enabling on port 25 for example would cause some inbound mail disruption... Even in this day and age.
MailEnable survivor / convert --