STARTTLS is an email-protocol command that upgrades an existing, unencrypted connection between a mail client and a mail server to an encrypted one using TLS (Transport Layer Security). Instead of opening a separate secure port, STARTTLS begins in plaintext and then switches the same connection to encryption — protecting your messages and login credentials while they travel.
How STARTTLS works
When a mail client connects to an SMTP server (typically on port 587), it issues the STARTTLS command. If the server supports it, the two negotiate a TLS session, and everything that follows — sender, recipients, message body, and authentication — travels encrypted. This is called explicit or opportunistic encryption, because the connection starts openly and is secured on request. If the server does not offer STARTTLS, the client can decide whether to continue in plaintext or stop.
STARTTLS vs SMTPS — and why it matters
STARTTLS (explicit TLS, usually port 587) and SMTPS (implicit TLS, port 465) reach the same goal — an encrypted email connection — by different routes. Encryption in transit keeps credentials and content private and supports compliance. Mailpro's SMTP service uses TLS 1.3 encryption from Swiss private infrastructure. Compare port 465 vs port 587 or check whether port 587 is always encrypted.
Sending transactional or bulk email over SMTP? Use Mailpro's Swiss SMTP relay with TLS encryption built in.
Mailpro and SMTP
Encrypted email delivery, hosted in Switzerland
Mailpro's SMTP relay sends your transactional and marketing email over TLS 1.3, from Swiss private infrastructure. In business since 2001, GDPR-native, with 9.6/10 self-reported deliverability.