Gmail opportunistic TLS distrusting LE-issued certificate

My SMTP server uses a Let’s Encrypt certificate for opportunistic STARTTLS on port 25. Yesterday, I started receiving connections from Google’s servers (mail-xxx-xxxxx.google.com) which would perform EHLO and STARTTLS then immediately drop the connection. When I later received an MTA-STS report, it reported failures for reason certificate-not-trusted (twelve failed sessions, spread across, apparently, 13 sending IP addresses—the total-failure-session-count was 12 but there were 13 entries in failure-details). According to my logs, these failures occurred from 2026-06-04 16:08:07 and 2026-06-05 05:41:44 UTC. As part of trying to debug the problem, I renewed my certificate, and that’s when the problem stopped. Curiously, my previous certificate was issued at 2026-05-05 21:50:50, which means the problems started just a few hours before 30 days from the time of issuance. The validity period ended 2026-08-03 21:50:49, so it was far from expired. The other difference I can see between the failing certificate and my current working certificate is that the failing certificate was issued by YE1 while the working one was issued by YE2.

Is this a known issue? Is it a random temporary failure on Google’s part, and the 30 day number was a complete coincidence? Is it an unknown-to-me policy change at Google to only trust SMTP opportunistic TLS certificates for 30 days? Any ideas? Thanks!

Failing certificate:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            05:af:4f:ee:98:81:15:ba:3e:d6:da:46:8f:82:14:96:21:bc
        Signature Algorithm: ecdsa-with-SHA384
        Issuer: C=US, O=Let's Encrypt, CN=YE1
        Validity
            Not Before: May  5 21:50:50 2026 GMT
            Not After : Aug  3 21:50:49 2026 GMT
        Subject: 
        Subject Public Key Info:
            Public Key Algorithm: id-ecPublicKey
                Public-Key: (256 bit)
                pub:
                    04:f7:9f:50:b9:8a:1c:d5:43:aa:34:8c:43:97:89:
                    76:32:44:b9:4f:60:4a:c0:c5:c2:66:4c:e9:e9:f1:
                    e5:79:c8:73:8a:d4:e8:22:9f:33:72:da:97:fa:96:
                    1d:20:ff:0c:dc:27:36:d2:84:7c:f3:d7:59:f9:ea:
                    e5:36:7f:ee:84
                ASN1 OID: prime256v1
                NIST CURVE: P-256
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication
            X509v3 Basic Constraints: critical
                CA:FALSE
            X509v3 Authority Key Identifier: 
                BB:20:CA:47:0B:FE:D7:E5:9C:F9:8F:09:2A:A3:8C:37:45:B1:BC:D8
            Authority Information Access: 
                CA Issuers - URI:http://ye1.i.lencr.org/
            X509v3 Subject Alternative Name: critical
                DNS:chead.ca, DNS:git.chead.ca, DNS:lovelace.chead.ca, DNS:mta-sts.chead.ca, DNS:openpgpkey.chead.ca, DNS:pim.chead.ca, DNS:www.chead.ca
            X509v3 Certificate Policies: 
                Policy: 2.23.140.1.2.1
            X509v3 CRL Distribution Points: 
                Full Name:
                  URI:http://ye1.c.lencr.org/61.crl

            CT Precertificate SCTs: 
                Signed Certificate Timestamp:
                    Version   : v1 (0x0)
                    Log ID    : AF:67:88:3B:57:B0:4E:DD:8F:A6:D9:7E:F6:2E:A8:EB:
                                81:0A:C7:71:60:F0:24:5E:55:D6:0C:2F:E7:85:87:3A
                    Timestamp : May  5 22:49:21.280 2026 GMT
                    Extensions: none
                    Signature : ecdsa-with-SHA256
                                30:45:02:20:02:A7:E0:79:3D:F5:45:5B:30:D8:DE:6F:
                                99:93:36:E2:98:2C:2D:C4:FE:CF:98:8B:99:62:81:9D:
                                F6:E2:CC:47:02:21:00:87:D3:9E:E0:43:C9:2B:14:8C:
                                D1:57:49:F6:D7:2D:11:66:6B:C6:63:73:36:12:C1:0D:
                                9B:EF:73:2C:3F:F3:BC
                Signed Certificate Timestamp:
                    Version   : v1 (0x0)
                    Log ID    : A8:26:CB:E3:0A:C6:35:12:46:53:3F:E0:65:F1:4F:19:
                                D9:6E:19:08:13:C4:1D:D9:6D:79:00:B3:12:3C:55:27
                    Timestamp : May  5 22:49:21.497 2026 GMT
                    Extensions: 00:00:05:00:09:B2:1B:01
                    Signature : ecdsa-with-SHA256
                                30:44:02:20:29:49:C4:D6:92:BA:2E:1F:0A:C8:39:AD:
                                FE:2C:CC:E8:FA:77:C5:0E:06:F4:03:64:49:4D:19:A2:
                                B5:1B:BE:0A:02:20:13:04:82:71:91:46:71:6E:EA:8A:
                                9E:C1:1A:A8:93:23:7A:1D:C0:71:C7:03:A8:E2:0A:18:
                                EB:FA:86:D7:11:C7
    Signature Algorithm: ecdsa-with-SHA384
    Signature Value:
        30:65:02:30:5e:d3:04:fe:d6:02:1a:2b:32:be:77:4e:e5:0b:
        d1:cf:44:73:77:0b:f6:78:1d:18:81:e0:05:5d:24:5e:f6:3e:
        8e:5d:bf:48:50:0c:9e:9e:d0:67:5b:12:e3:27:ce:35:02:31:
        00:de:13:0c:b5:fa:dd:ab:59:08:f7:6b:f7:fd:fa:82:62:8e:
        5e:dd:95:df:ed:db:8a:4b:c5:0b:ba:f6:70:d4:b2:f0:fb:71:
        27:a5:7c:8e:dd:c1:c5:06:fe:fc:63:d1:01
-----BEGIN CERTIFICATE-----
MIIDsjCCAzigAwIBAgISBa9P7piBFbo+1tpGj4IUliG8MAoGCCqGSM49BAMDMDMx
CzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MQwwCgYDVQQDEwNZ
RTEwHhcNMjYwNTA1MjE1MDUwWhcNMjYwODAzMjE1MDQ5WjAAMFkwEwYHKoZIzj0C
AQYIKoZIzj0DAQcDQgAE959QuYoc1UOqNIxDl4l2MkS5T2BKwMXCZkzp6fHlechz
itToIp8zctqX+pYdIP8M3Cc20oR889dZ+erlNn/uhKOCAl0wggJZMA4GA1UdDwEB
/wQEAwIHgDATBgNVHSUEDDAKBggrBgEFBQcDATAMBgNVHRMBAf8EAjAAMB8GA1Ud
IwQYMBaAFLsgykcL/tflnPmPCSqjjDdFsbzYMDMGCCsGAQUFBwEBBCcwJTAjBggr
BgEFBQcwAoYXaHR0cDovL3llMS5pLmxlbmNyLm9yZy8wegYDVR0RAQH/BHAwboII
Y2hlYWQuY2GCDGdpdC5jaGVhZC5jYYIRbG92ZWxhY2UuY2hlYWQuY2GCEG10YS1z
dHMuY2hlYWQuY2GCE29wZW5wZ3BrZXkuY2hlYWQuY2GCDHBpbS5jaGVhZC5jYYIM
d3d3LmNoZWFkLmNhMBMGA1UdIAQMMAowCAYGZ4EMAQIBMC4GA1UdHwQnMCUwI6Ah
oB+GHWh0dHA6Ly95ZTEuYy5sZW5jci5vcmcvNjEuY3JsMIIBCwYKKwYBBAHWeQIE
AgSB/ASB+QD3AHYAr2eIO1ewTt2Pptl+9i6o64EKx3Fg8CReVdYML+eFhzoAAAGd
+lTmgAAABAMARzBFAiACp+B5PfVFWzDY3m+ZkzbimCwtxP7PmIuZYoGd9uLMRwIh
AIfTnuBDySsUjNFXSfbXLRFma8ZjczYSwQ2b73MsP/O8AH0AqCbL4wrGNRJGUz/g
ZfFPGdluGQgTxB3ZbXkAsxI8VScAAAGd+lTnWQAIAAAFAAmyGwEEAwBGMEQCIClJ
xNaSui4fCsg5rf4szOj6d8UOBvQDZElNGaK1G74KAiATBIJxkUZxbuqKnsEaqJMj
eh3AcccDqOIKGOv6htcRxzAKBggqhkjOPQQDAwNoADBlAjBe0wT+1gIaKzK+d07l
C9HPRHN3C/Z4HRiB4AVdJF72Po5dv0hQDJ6e0GdbEuMnzjUCMQDeEwy1+t2rWQj3
a/f9+oJijl7dld/t24pLxQu69nDUsvD7cSelfI7dwcUG/vxj0QE=
-----END CERTIFICATE-----

Working replacement certificate:

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            05:6a:fe:cc:03:03:b2:8a:57:20:72:84:a7:55:b1:96:97:41
        Signature Algorithm: ecdsa-with-SHA384
        Issuer: C=US, O=Let's Encrypt, CN=YE2
        Validity
            Not Before: Jun  5 04:56:21 2026 GMT
            Not After : Sep  3 04:56:20 2026 GMT
        Subject: CN=chead.ca
        Subject Public Key Info:
            Public Key Algorithm: id-ecPublicKey
                Public-Key: (256 bit)
                pub:
                    04:c4:e9:d7:a9:17:16:38:f3:5c:d7:4c:d0:2e:71:
                    2c:4e:d9:99:f5:ba:a6:13:c6:b8:40:e4:b9:bf:1b:
                    d8:d9:82:7b:88:6b:bd:15:5f:09:08:d3:ac:e9:4e:
                    27:18:4d:74:01:0a:bd:18:8a:ac:10:07:91:a0:71:
                    f7:0f:ae:c4:34
                ASN1 OID: prime256v1
                NIST CURVE: P-256
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature
            X509v3 Extended Key Usage: 
                TLS Web Server Authentication
            X509v3 Basic Constraints: critical
                CA:FALSE
            X509v3 Subject Key Identifier: 
                B8:62:36:77:68:4F:9D:9C:BD:A3:E0:30:60:7B:04:D4:6C:BA:78:AC
            X509v3 Authority Key Identifier: 
                B9:59:F2:8E:CF:22:F0:86:D3:37:48:FF:76:14:18:BA:82:D8:55:87
            Authority Information Access: 
                CA Issuers - URI:http://ye2.i.lencr.org/
            X509v3 Subject Alternative Name: 
                DNS:chead.ca, DNS:git.chead.ca, DNS:lovelace.chead.ca, DNS:mta-sts.chead.ca, DNS:openpgpkey.chead.ca, DNS:pim.chead.ca, DNS:www.chead.ca
            X509v3 Certificate Policies: 
                Policy: 2.23.140.1.2.1
            X509v3 CRL Distribution Points: 
                Full Name:
                  URI:http://ye2.c.lencr.org/66.crl

            CT Precertificate SCTs: 
                Signed Certificate Timestamp:
                    Version   : v1 (0x0)
                    Log ID    : D7:6D:7D:10:D1:A7:F5:77:C2:C7:E9:5F:D7:00:BF:F9:
                                82:C9:33:5A:65:E1:D0:B3:01:73:17:C0:C8:C5:69:77
                    Timestamp : Jun  5 05:54:51.278 2026 GMT
                    Extensions: none
                    Signature : ecdsa-with-SHA256
                                30:46:02:21:00:81:BC:FD:A8:60:D9:1B:57:F7:80:67:
                                4C:87:6C:CB:B1:48:43:A4:19:DC:5B:64:51:B8:16:97:
                                54:B1:C1:90:07:02:21:00:A7:6A:73:D7:62:50:4C:89:
                                80:D9:42:CB:FC:2B:00:AB:38:16:B0:13:34:D0:B8:50:
                                9F:31:1F:2B:A3:4D:59:44
                Signed Certificate Timestamp:
                    Version   : v1 (0x0)
                    Log ID    : 1A:8B:9D:6B:0F:FE:BF:81:B4:79:39:C6:D2:31:0A:86:
                                D6:D1:02:D4:F0:46:E2:18:2C:9D:E3:5F:5E:26:25:EF
                    Timestamp : Jun  5 05:54:51.701 2026 GMT
                    Extensions: 00:00:05:00:1A:CC:79:B6
                    Signature : ecdsa-with-SHA256
                                30:46:02:21:00:A4:EA:78:71:0E:1A:40:82:95:9D:0C:
                                4D:48:54:1E:A5:78:58:0A:DD:1C:F2:EA:DF:03:32:33:
                                01:3A:D6:2F:C4:02:21:00:AC:2B:B0:53:21:71:D2:86:
                                6D:EE:A0:87:06:84:B9:E6:42:FF:74:45:9A:7A:70:BD:
                                36:8C:D2:01:28:5D:60:AB
    Signature Algorithm: ecdsa-with-SHA384
    Signature Value:
        30:65:02:30:39:63:e0:6c:2c:50:79:08:86:c4:93:6f:7c:18:
        97:15:db:ee:bf:33:87:f2:18:d4:c7:02:23:a7:be:75:cb:de:
        ac:3b:29:f0:38:b0:37:4f:5b:11:e3:b7:2b:df:04:e2:02:31:
        00:cb:25:c5:14:0d:50:c0:89:40:15:35:11:f4:d0:39:33:ac:
        fd:88:7b:68:86:d0:1e:b0:93:88:4d:eb:59:b1:a2:15:e5:69:
        c2:4a:11:aa:03:76:bc:c9:28:c2:f3:39:f3
-----BEGIN CERTIFICATE-----
MIID5DCCA2qgAwIBAgISBWr+zAMDsopXIHKEp1WxlpdBMAoGCCqGSM49BAMDMDMx
CzAJBgNVBAYTAlVTMRYwFAYDVQQKEw1MZXQncyBFbmNyeXB0MQwwCgYDVQQDEwNZ
RTIwHhcNMjYwNjA1MDQ1NjIxWhcNMjYwOTAzMDQ1NjIwWjATMREwDwYDVQQDEwhj
aGVhZC5jYTBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABMTp16kXFjjzXNdM0C5x
LE7ZmfW6phPGuEDkub8b2NmCe4hrvRVfCQjTrOlOJxhNdAEKvRiKrBAHkaBx9w+u
xDSjggJ8MIICeDAOBgNVHQ8BAf8EBAMCB4AwEwYDVR0lBAwwCgYIKwYBBQUHAwEw
DAYDVR0TAQH/BAIwADAdBgNVHQ4EFgQUuGI2d2hPnZy9o+AwYHsE1Gy6eKwwHwYD
VR0jBBgwFoAUuVnyjs8i8IbTN0j/dhQYuoLYVYcwMwYIKwYBBQUHAQEEJzAlMCMG
CCsGAQUFBzAChhdodHRwOi8veWUyLmkubGVuY3Iub3JnLzB3BgNVHREEcDBugghj
aGVhZC5jYYIMZ2l0LmNoZWFkLmNhghFsb3ZlbGFjZS5jaGVhZC5jYYIQbXRhLXN0
cy5jaGVhZC5jYYITb3BlbnBncGtleS5jaGVhZC5jYYIMcGltLmNoZWFkLmNhggx3
d3cuY2hlYWQuY2EwEwYDVR0gBAwwCjAIBgZngQwBAgEwLgYDVR0fBCcwJTAjoCGg
H4YdaHR0cDovL3llMi5jLmxlbmNyLm9yZy82Ni5jcmwwggEOBgorBgEEAdZ5AgQC
BIH/BIH8APoAdwDXbX0Q0af1d8LH6V/XAL/5gskzWmXh0LMBcxfAyMVpdwAAAZ6W
WT0OAAAEAwBIMEYCIQCBvP2oYNkbV/eAZ0yHbMuxSEOkGdxbZFG4FpdUscGQBwIh
AKdqc9diUEyJgNlCy/wrAKs4FrATNNC4UJ8xHyujTVlEAH8AGoudaw/+v4G0eTnG
0jEKhtbRAtTwRuIYLJ3jX14mJe8AAAGellk+tQAIAAAFABrMebYEAwBIMEYCIQCk
6nhxDhpAgpWdDE1IVB6leFgK3Rzy6t8DMjMBOtYvxAIhAKwrsFMhcdKGbe6ghwaE
ueZC/3RFmnpwvTaM0gEoXWCrMAoGCCqGSM49BAMDA2gAMGUCMDlj4GwsUHkIhsST
b3wYlxXb7r8zh/IY1McCI6e+dcverDsp8DiwN09bEeO3K98E4gIxAMslxRQNUMCJ
QBU1EfTQOTOs/Yh7aIbQHrCTiE3rWbGiFeVpwkoRqgN2vMkowvM58w==
-----END CERTIFICATE-----

My domain is: lovelace.chead.ca

My mail server is (include version): Exim 4.99.3

The operating system my mail server runs on is Linux 6.18.33

My hosting provider, if applicable, is: Fullhost

I can login to a root shell on my machine (yes or no, or I don't know): Yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel): No

The version of my client is (e.g. output of certbot --version or certbot-auto --version if you're using Certbot): Certbot 4.0.0

And in case it’s useful to anyone, I might as well also include the MTA-STS report:

{
  "organization-name": "Google Inc.",
  "date-range": {
    "start-datetime": "2026-06-04T00:00:00Z",
    "end-datetime": "2026-06-04T23:59:59Z"
  },
  "contact-info": "smtp-tls-reporting@google.com",
  "report-id": "2026-06-04T00:00:00Z_chead.ca",
  "policies": [
    {
      "policy": {
        "policy-type": "sts",
        "policy-string": [
          "version: STSv1",
          "mode: enforce",
          "max_age: 86400",
          "mx: lovelace.chead.ca"
        ],
        "policy-domain": "chead.ca",
        "mx-host": [
          "lovelace.chead.ca"
        ]
      },
      "summary": {
        "total-successful-session-count": 0,
        "total-failure-session-count": 12
      },
      "failure-details": [
        {
          "result-type": "certificate-not-trusted",
          "sending-mta-ip": "2607:f8b0:4864:20::a2d",
          "receiving-ip": "2001:470:1f2f:2f5:216:3cff:fef8:e1e9",
          "receiving-mx-hostname": "lovelace.chead.ca",
          "failed-session-count": 1
        },
        {
          "result-type": "certificate-not-trusted",
          "sending-mta-ip": "2607:f8b0:4864:20::936",
          "receiving-ip": "2001:470:1f2f:2f5:216:3cff:fef8:e1e9",
          "receiving-mx-hostname": "lovelace.chead.ca",
          "failed-session-count": 1
        },
        {
          "result-type": "certificate-not-trusted",
          "sending-mta-ip": "2607:f8b0:4864:20::747",
          "receiving-ip": "2001:470:1f2f:2f5:216:3cff:fef8:e1e9",
          "receiving-mx-hostname": "lovelace.chead.ca",
          "failed-session-count": 1
        },
        {
          "result-type": "certificate-not-trusted",
          "sending-mta-ip": "2607:f8b0:4864:20::1248",
          "receiving-ip": "2001:470:1f2f:2f5:216:3cff:fef8:e1e9",
          "receiving-mx-hostname": "lovelace.chead.ca",
          "failed-session-count": 1
        },
        {
          "result-type": "certificate-not-trusted",
          "sending-mta-ip": "2607:f8b0:4864:20::246",
          "receiving-ip": "2001:470:1f2f:2f5:216:3cff:fef8:e1e9",
          "receiving-mx-hostname": "lovelace.chead.ca",
          "failed-session-count": 1
        },
        {
          "result-type": "certificate-not-trusted",
          "sending-mta-ip": "2607:f8b0:4864:20::f47",
          "receiving-ip": "2001:470:1f2f:2f5:216:3cff:fef8:e1e9",
          "receiving-mx-hostname": "lovelace.chead.ca",
          "failed-session-count": 1
        },
        {
          "result-type": "certificate-not-trusted",
          "sending-mta-ip": "2607:f8b0:4864:20::92f",
          "receiving-ip": "2001:470:1f2f:2f5:216:3cff:fef8:e1e9",
          "receiving-mx-hostname": "lovelace.chead.ca",
          "failed-session-count": 1
        },
        {
          "result-type": "certificate-not-trusted",
          "sending-mta-ip": "2607:f8b0:4864:20::847",
          "receiving-ip": "2001:470:1f2f:2f5:216:3cff:fef8:e1e9",
          "receiving-mx-hostname": "lovelace.chead.ca",
          "failed-session-count": 1
        },
        {
          "result-type": "certificate-not-trusted",
          "sending-mta-ip": "2607:f8b0:4864:20::e29",
          "receiving-ip": "2001:470:1f2f:2f5:216:3cff:fef8:e1e9",
          "receiving-mx-hostname": "lovelace.chead.ca",
          "failed-session-count": 1
        },
        {
          "result-type": "certificate-not-trusted",
          "sending-mta-ip": "2607:f8b0:4864:20::1133",
          "receiving-ip": "2001:470:1f2f:2f5:216:3cff:fef8:e1e9",
          "receiving-mx-hostname": "lovelace.chead.ca",
          "failed-session-count": 1
        },
        {
          "result-type": "certificate-not-trusted",
          "sending-mta-ip": "2607:f8b0:4864:20::1129",
          "receiving-ip": "2001:470:1f2f:2f5:216:3cff:fef8:e1e9",
          "receiving-mx-hostname": "lovelace.chead.ca",
          "failed-session-count": 1
        },
        {
          "result-type": "certificate-not-trusted",
          "sending-mta-ip": "2607:f8b0:4864:20::a2e",
          "receiving-ip": "2001:470:1f2f:2f5:216:3cff:fef8:e1e9",
          "receiving-mx-hostname": "lovelace.chead.ca",
          "failed-session-count": 1
        },
        {
          "result-type": "certificate-not-trusted",
          "sending-mta-ip": "2607:f8b0:4864:20::e2d",
          "receiving-ip": "2001:470:1f2f:2f5:216:3cff:fef8:e1e9",
          "receiving-mx-hostname": "lovelace.chead.ca",
          "failed-session-count": 1
        }
      ]
    }
  ]
}

Welcome @Hawk777

I can't explain all the twists and turns but it is most likely related to a Let's Encrypt incident that required revoking some of their intermediates. Why that only caused problems for you in recent days I can't explain. Maybe it took that long for google's mail servers to recognize or honor the revocations? See the incident here: 2026.05.08 Gen Y Cross-Certified Subordinate CAs missing serverAuth EKU

During that incident LE triggered ARI renewals so capable systems would renew their certs immediately. Sadly, your Certbot v4.0 does not support ARI. You would need at least v4.1 for that. See: certbot/certbot/CHANGELOG.md at main · certbot/certbot · GitHub I'm guessing that v4.0 came from your pkg manager. You may want to consider using the snap or pip install instead. See: https://certbot.eff.org

That has no bearing on this or what you've seen. LE uses YE1 or YE2 at random for various reasons.

Thanks for the reply. That looks very likely to be the case: the old chain did indeed end with X2 signed by X1 without EKU, and the new chain ends with X2 signed by X1 with EKU. My previous-previous chain also ended with that same X2 without EKU, so I guess I have had such chains for a while and Google only just started caring about them.

I realize Certbot 4 is a bit old. It did come from my package manager. Newer versions are available but not deemed stable by the distro yet, so I’ve avoided them, but they will be stabilized and then I’ll get ARI support :tada:. For various reasons which are probably off-topic I’m not interested in alternative install methods.

Perhaps it was related to that. But, the intermediate was revoked as a result of that incident. While LE reported the revocations on the CRL google may have delayed enforcing that until people had more time to update their sytems (non-ARI systems). Just my educated guess.

Understand reluctance for snap or pip. I don't care for them either.

Certbot has delayed adding new features compared to other clients. ARI, for example, was introduced by LE about 2 years before Certbot supported it. The lego ACME Client is often very prompt to get new features. Tradeoffs, I know. Until you get ARI support you should subscribe to the Incidents section of this forum so you can learn about CA events and react accordingly.

Ah, propagation of the CRL is a much better explanation than mine. Good news is, my distro just a few days ago declared Certbot 5.5 stable, so my next update will give me that, making it all academic! I’m also reluctant to switch clients given how much configuration goes into it, and I prefer a client that uses dns-rfc2136, which IIRC a number of the alternatives don’t (I’m not using wildcard certs, but I do have quite a lot of SANs, so it’s easier to use a DNS-based validation than trying to wrangle my web server to serve up the validation files on all the different hostnames).

That is good news.

Fair enough. lego supports hundreds of DNS providers including that: DNS Update (RFC2136) :: ACME client and library written in Go.

Perhaps an even easier path forward is to keep watch for dns-persist-01 challenge. It is currently available only in Let's Encrypt's Staging system. Allows setting up a TXT record just once. See: DNS-PERSIST-01: A New Model for DNS-based Challenge Validation - Let's Encrypt

Of course, your ACME Client needs support for it then too. And for your package maintainer to bring that onboard :slight_smile: Not that I'm pitching lego but it already supports draft v01 of the RFC for dns-persist. I make these comments more to highlight there are options. As always, tradeoffs I know.

Oh, dns-persist-01 looks really nice. That’s something to look forward to! Let’s Encrypt is currently the only reason why my main zone is dynamic at all, and that would let me bring it back to static. Thanks again for all the ideas; lots to consider.

You have set STS to enforcing. It's mandatory, not opportunistic any more.

I suppose that’s half true. It’s mandatory for peers who look at MTA-STS records, and opportunistic for those who don’t. Just so used to calling it opportunistic for historical reasons since STARTTLS on 25 used to only be opportunistic.