Email Verification with Self-Hosted

(#642) Bug Needs triage self-hosting

Summary

When I register a new account with my instance, I am unable to verify emails. When attempting to resend the email verification I get the following error:
{"level":"error","time":"2026-06-18T13:30:58.589Z","service":"@pkgs/email/src/SmtpEmailProvider","env":"production","error":{"type":"Error","message":"401DD450667F0000:error:0A00010B:SSL routines:tls_validate_record_header:wrong version number:../deps/openssl/openssl/ssl/record/methods/tlsany_meth.c:77:\n","stack":"Error: 401DD450667F0000:error:0A00010B:SSL routines:tls_validate_record_header:wrong version number:../deps/openssl/openssl/ssl/record/methods/tlsany_meth.c:77:\n","library":"SSL routines","reason":"wrong version number","code":"ESOCKET","command":"CONN"},"msg":"SMTP send failed"}
{"level":"info","time":"2026-06-18T13:30:58.589Z","service":"fluxer-api","env":"production","method":"POST","path":"/v1/auth/verify/resend","status":204,"durationMs":209,"msg":"Request completed"}
I am using outlook basic auth with starttls for my smtp provider. This is my .env
FLUXER_EMAIL_ENABLED=true
FLUXER_EMAIL_PROVIDER=smtp
FLUXER_EMAIL_FROM_EMAIL=myemail@outlook.com
FLUXER_EMAIL_FROM_NAME=aaron
FLUXER_EMAIL_SMTP_HOST=smtp-mail.outlook.com
FLUXER_EMAIL_SMTP_PORT=587
FLUXER_EMAIL_SMTP_USERNAME=myemail@outlook.com
FLUXER_EMAIL_SMTP_PASSWORD=app_password
FLUXER_EMAIL_SMTP_SECURE=true
I have the same exact settings applied in the /admin/instance-config. I have also tried my zoho email with my domain email.

Steps to reproduce

Edit .env and /admin/instance-config settings for SMTP. I have tried numerous variations with different ports (25 and 465), with/without tls and the SECURE env variable, even though I am 100% confident I am using the correct settings (other self-hosted services setup successfully with this same SMTP config).

Environment

PRETTY_NAME="Debian GNU/Linux 13 (trixie)" NAME="Debian GNU/Linux" VERSION_ID="13" VERSION="13 (trixie)" VERSION_CODENAME=trixie DEBIAN_VERSION_FULL=13.5 ID=debian HOME_URL="https://www.debian.org/" SUPPORT_URL="https://www.debian.org/support" BUG_REPORT_URL="https://bugs.debian.org/"

Logs or screenshots

{"level":"error","time":"2026-06-18T13:30:58.589Z","service":"[@pkgs/email](https://github.com/orgs/pkgs/teams/email)/src/SmtpEmailProvider","env":"production","error":{"type":"Error","message":"401DD450667F0000:error:0A00010B:SSL routines:tls_validate_record_header:wrong version number:../deps/openssl/openssl/ssl/record/methods/tlsany_meth.c:77:\n","stack":"Error: 401DD450667F0000:error:0A00010B:SSL routines:tls_validate_record_header:wrong version number:../deps/openssl/openssl/ssl/record/methods/tlsany_meth.c:77:\n","library":"SSL routines","reason":"wrong version number","code":"ESOCKET","command":"CONN"},"msg":"SMTP send failed"}
{"level":"info","time":"2026-06-18T13:30:58.589Z","service":"fluxer-api","env":"production","method":"POST","path":"/v1/auth/verify/resend","status":204,"durationMs":209,"msg":"Request completed"}

15 comments

Sign in with Fluxer to comment and vote.
Comment by @pekempy
RexSystem 1 vote originally by @pekempy on GitHub
Try disabling TLS, I disabled TLS and emails started coming through
Comment by @adavi1995
RexSystem 1 vote originally by @adavi1995 on GitHub OP
Thanks for the response. That was one of the things I have tried and still had failure in sending emails. I believe starttls requires tls to be selected Edit: I get the following error with TLS disabled
{"level":"info","time":"2026-06-18T14:31:46.397Z","service":"fluxer-api","env":"production","method":"GET","path":"/.well-known/fluxer","status":200,"durationMs":2,"msg":"Request completed"}
{"level":"error","time":"2026-06-18T14:31:52.614Z","service":"@pkgs/email/src/SmtpEmailProvider","env":"production","error":{"type":"Error","message":"Invalid login: 535 5.7.139 Authentication unsuccessful, basic authentication is disabled. [MW4PR04CA0174.namprd04.prod.outlook.com 2026-06-18T14:31:52.609Z 08DECD122969F67B]","stack":"Error: Invalid login: 535 5.7.139 Authentication unsuccessful, basic authentication is disabled. [MW4PR04CA0174.namprd04.prod.outlook.com 2026-06-18T14:31:52.609Z 08DECD122969F67B]\n    at SMTPConnection._formatError (/usr/src/app/fluxer_api/node_modules/.pnpm/nodemailer@8.0.1/node_modules/nodemailer/lib/smtp-connection/index.js:912:19)\n    at SMTPConnection._actionAUTHComplete (/usr/src/app/fluxer_api/node_modules/.pnpm/nodemailer@8.0.1/node_modules/nodemailer/lib/smtp-connection/index.js:1722:34)\n    at SMTPConnection.<anonymous> (/usr/src/app/fluxer_api/node_modules/.pnpm/nodemailer@8.0.1/node_modules/nodemailer/lib/smtp-connection/index.js:1676:18)\n    at SMTPConnection._processResponse (/usr/src/app/fluxer_api/node_modules/.pnpm/nodemailer@8.0.1/node_modules/nodemailer/lib/smtp-connection/index.js:1098:20)\n    at SMTPConnection._onData (/usr/src/app/fluxer_api/node_modules/.pnpm/nodemailer@8.0.1/node_modules/nodemailer/lib/smtp-connection/index.js:872:14)\n    at SMTPConnection._onSocketData (/usr/src/app/fluxer_api/node_modules/.pnpm/nodemailer@8.0.1/node_modules/nodemailer/lib/smtp-connection/index.js:196:44)\n    at TLSSocket.emit (node:events:509:28)\n    at addChunk (node:internal/streams/readable:563:12)\n    at readableAddChunkPushByteMode (node:internal/streams/readable:514:3)\n    at Readable.push (node:internal/streams/readable:394:5)","code":"EAUTH","response":"535 5.7.139 Authentication unsuccessful, basic authentication is disabled. [MW4PR04CA0174.namprd04.prod.outlook.com 2026-06-18T14:31:52.609Z 08DECD122969F67B]","responseCode":535,"command":"AUTH LOGIN"},"msg":"SMTP send failed"}
{"level":"info","time":"2026-06-18T14:31:52.615Z","service":"fluxer-api","env":"production","method":"POST","path":"/v1/auth/verify/resend","status":204,"durationMs":5957,"msg":"Request completed"}
Comment by @vulpeace
RexSystem 1 vote originally by @vulpeace on GitHub
It's not a bug. The first error message is caused by the wrong port for TLS SMTP, the second one – by Outlook's requirement of Oauth2. Something like resend.com will work just fine. It's pretty user-friendly too :)
Comment by @adavi1995
RexSystem 1 vote originally by @adavi1995 on GitHub OP
It's not a bug. The first error message is caused by the wrong port for TLS SMTP, the second one – by Outlook's requirement of Oauth2. Something like resend.com will work just fine. It's pretty user-friendly too :)
I could be missing something still. My understanding is to use port 587 for TLS/STARTTLS, which produced the first error.. 465 would be used to upgrade to a TLS connection, but I have tried that as well and still, unsuccessful. You're saying for me to sign up with resend.com? That is something I can try out too, but would prefer this to just work with my outlook. Zoho is similar to resend it looks like, but I get failures with that account too
Comment by @adavi1995
RexSystem 1 vote originally by @adavi1995 on GitHub OP
I have now tried with my outlook and zoho - port 465 with and without tls enabled port 587 with and without tls enabled .env smtp config - empty and the above combinations.
Comment by @Gaarindor
RexSystem 1 vote originally by @Gaarindor on GitHub
I am getting a very similar error using Proton Mail as my SMTP provider and have managed to patch the container to make it work. Only a temp solution while the containers are up. Error in logs:
{"level":"error","time":"2026-06-21T00:25:56.366Z","service":"@pkgs/email/src/SmtpEmailProvider","env":"production","error":{"type":"Error","message":"401D5C8A577F0000:error:0A00010B:SSL routines:tls_validate_record_header:wrong version number:../deps/openssl/openssl/ssl/record/methods/tlsany_meth.c:77:\n","stack":"Error: 401D5C8A577F0000:error:0A00010B:SSL routines:tls_validate_record_header:wrong version number:../deps/openssl/openssl/ssl/record/methods/tlsany_meth.c:77:\n","library":"SSL routines","reason":"wrong version number","code":"ESOCKET","command":"CONN"},"msg":"SMTP send failed"}
To get it working I have set the below: .env
FLUXER_EMAIL_ENABLED=true
FLUXER_EMAIL_PROVIDER=smtp
FLUXER_EMAIL_FROM_EMAIL=support@example.com
FLUXER_EMAIL_FROM_NAME=Fluxer Support
FLUXER_EMAIL_SMTP_HOST=smtp.protonmail.ch
FLUXER_EMAIL_SMTP_PORT=587
FLUXER_EMAIL_SMTP_USERNAME=support@example.com
FLUXER_EMAIL_SMTP_PASSWORD=xxxxxxxxxxxxxxx
FLUXER_EMAIL_SMTP_SECURE=false
In the api container fluxer-api-1 I am getting issues against the SmtpEmailProvider.ts file. It seems like the boolean isn't working as expected. usr/src/app/fluxer_api/node_modules/.pnpm/@pkgs+email@file+fluxer_api+pkgs+email/node_modules/@pkgs/email/src/SmtpEmailProvider.ts In SmtpEmailProvider.ts secure: config.secure ?? true is not passing correctly for me. I patched the api container to update it to secure: config.secure !== undefined ? config.secure === "true" : true" and restarted the api container. It is now working. Replicate: api container
# Patch
docker exec fluxer-api-1 sed -i 's/secure: config.secure ?? true/secure: config.secure !== undefined ? config.secure === "true" : true/g' /usr/src/app/fluxer_api/node_modules/.pnpm/@pkgs+email@file+fluxer_api+pkgs+email/node_modules/@pkgs/email/src/SmtpEmailProvider.ts

# Verify
docker exec fluxer-api-1 grep "secure:" /usr/src/app/fluxer_api/node_modules/.pnpm/@pkgs+email@file+fluxer_api+pkgs+email/node_modules/@pkgs/email/src/SmtpEmailProvider.ts

# Restart just the API
docker compose restart api
and worker as well
docker exec fluxer-worker-1 sed -i 's/secure: config.secure ?? true/secure: config.secure !== undefined ? config.secure === "true" : true/g' /usr/src/app/fluxer_api/node_modules/.pnpm/@pkgs+email@file+fluxer_api+pkgs+email/node_modules/@pkgs/email/src/SmtpEmailProvider.ts

docker compose restart worker
Comment by @vulpeace
RexSystem 1 vote edited originally by @vulpeace on GitHub
secure: config.secure !== undefined ? config.secure === "true" : true"
@Gaarindor Sorry if i'm missing something. config.secure === "true" is always false, right? So, you basically forced config.secure to false, and then it started working with the port 587, which is expected. And it does not work if you only set FLUXER_EMAIL_SMTP_SECURE=false and FLUXER_EMAIL_SMTP_PORT=587 without touching the code?
Comment by @Gaarindor
RexSystem 1 vote edited originally by @Gaarindor on GitHub
@vulpeace Yes, changing FLUXER_EMAIL_SMTP_SECURE to true or false before any code changes does nothing / always fails. Correct with code change as well. I am trying to re-build the line as it seems to be boolean behaviour to me? When I set FLUXER_EMAIL_SMTP_SECURE=true in .env it seems to still fall to false as well from my testing. Hard coding true in code results in my emails no longer working.
Comment by @vulpeace
RexSystem 1 vote edited originally by @vulpeace on GitHub
When I set FLUXER_EMAIL_SMTP_SECURE=true in .env it seems to still fall to false as well from my testing. Hard coding true in code results in my emails no longer working.
@Gaarindor That's what initially puzzled me the most — i've thought that the bug is that they'd used string type for config.secure, but it is actually bool and you're comparing it to a string 🤔 I have no idea about the rest, unfortunately. 587 should be used with tls off, which works for me, and 465 is for tls on, also working.
Comment by @astroslav
RexSystem 1 vote edited originally by @astroslav on GitHub
@Gaarindor I can confirm that after following your steps, e-mails are now being sent.
Comment by @adavi1995
RexSystem 1 vote edited originally by @adavi1995 on GitHub OP
@vulpeace, I understand the enforcement of Oauth2, and that is not what I am using. Outlook enforces Oauth2, but also allows app passwords for "legacy" type authentication. What I am using is the app password, which I have had work with several other services I self-host. So, I would like to confirm - this is a bug then?
Comment by @LokeYourC3PH
RexSystem 1 vote originally by @LokeYourC3PH on GitHub
This seems very much to be a bug because I am facing this issue as well, and other services I use on the same system that send mail via SMTP work perfectly fine.
Deleted comment
Removed by moderator Rex: Removed a general status note that was posted on many GitHub threads. It no longer applies here.
Comment by @emptyynes
RexSystem 1 vote originally by @emptyynes on GitHub
  • 659795982-9cda06a3-e7c8-46cc-8c73-9ee3af2ab629.webp

    659795982-9cda06a3-e7c8-46cc-8c73-9ee3af2ab629.webp

    486×682 | 58 kB

Off-topic comment by @emptyynes
RexSystem 1 vote originally by @emptyynes on GitHub Collapsed as off-topic by Rex: A one-word bump asking when.
когда