Deliverability

Fix: STARTTLS not supported / must issue STARTTLS first

What "STARTTLS not supported / must issue STARTTLS first" means and exactly how to fix it — with the DNS or client change that resolves it for good.

Seeing "STARTTLS not supported / must issue STARTTLS first"? Here is what it actually means and the specific fix — not generic advice. Most email errors trace back to DNS or an encryption setting, and both are quick to correct.

Quick summary

  • Enable STARTTLS on port 587 in your client.
  • Do not use plain/no-encryption — the server requires TLS.
  • If the client only offers SSL/TLS, point it at 993 for IMAP and 587 STARTTLS for SMTP.
  • Send a test message and check it lands in the inbox, not spam.
  • In Gmail, use "Show original" to confirm SPF, DKIM and DMARC all pass.

What is happening

The client tried to authenticate before upgrading the connection to TLS.

How to fix it

  1. Enable STARTTLS on port 587 in your client.
  2. Do not use plain/no-encryption — the server requires TLS.
  3. If the client only offers SSL/TLS, point it at 993 for IMAP and 587 STARTTLS for SMTP.

Confirm it is resolved

  • Send a test message and check it lands in the inbox, not spam.
  • In Gmail, use "Show original" to confirm SPF, DKIM and DMARC all pass.
  • If it persists, re-verify your domain in the OquMail dashboard.

Common questions

How long does fix take for a small business?

Most teams finish domain connection and first mailboxes in under an hour. DNS propagation is often minutes; in rare cases wait up to 24–48 hours. OquMail shows live verification so you know when you are ready.

Do I need technical experience to set up business email?

No. If you can log into where you bought your domain and paste a few lines of text, you can set up professional email. OquMail guides you step by step and verifies when DNS is correct.

Can my small team use business email for free?

Yes. OquMail's free plan includes up to 15 mailboxes on your own domain with webmail, guided SPF/DKIM/DMARC setup, and a transactional email API — no credit card required.

Free business email on your own domain

OquMail gives you up to 15 mailboxes on your domain — free — with guided SPF/DKIM/DMARC, webmail, IMAP/SMTP for any mail app, and a send API. Most teams are live in under fifteen minutes. Start at oqumail.com.

Get started free

Ready for business email on your domain?

Up to 15 free mailboxes, guided DNS, webmail, and a transactional API — start in minutes.

Create your free workspace
Deliverability

Fix: SPF PermError: too many DNS lookups

What "SPF PermError: too many DNS lookups" means and exactly how to fix it — with the DNS or client change that resolves it for good.

July 5, 2026

Deliverability

Fix: DKIM signature did not verify

What "DKIM signature did not verify" means and exactly how to fix it — with the DNS or client change that resolves it for good. Practical guide for…

July 5, 2026