I’m seeing more and more questions related to this and wanted to put how to fix it out there for folks.

Gmail has started flagging emails that were sent without encryption using a small red lock. It looks like this:

Screenshot from 2016-02-17 12:23:16

To fix this is pretty easy with Postfix.

  1. Log in to the server
  2. Open up /etc/postfix/
  3. Ensure the following values are set:
  4. smtpd_tls_security_level = may
    smtp_tls_security_level = may
    smtp_tls_loglevel = 1
    smtpd_tls_loglevel = 1

    (there are three levels you can set: none, may, or encrypt. Using may ensures we don’t lock out those who can’t do encryption)

  5. Reload postfix: service postfix reload
  6. Send a test email and check gmail. You should now see that there is no broken lock:

Screenshot from 2016-02-17 12:27:08

