There was a problem loading the comments.

Email Security Update: TLS 1.2 Requirement

Support Portal  »  Knowledgebase  »  Viewing Article

Email Security Update: TLS 1.2 Requirement

Effective 1 February 2026, DreamIT Host will require all email connections to use TLS 1.2 or higher encryption. Insecure ports (25, 110, 143) without encryption will be disabled.

Customers using outdated email clients or operating systems that do not support TLS 1.2 will need to upgrade to continue accessing their email.

⚠️ Action Required: Review the compatibility tables below to confirm your email client supports TLS 1.2. Update your settings or upgrade your software before 1 February 2026.

Ports Being Disabled

Port Protocol Status After 1 Feb 2026
25 SMTP (unencrypted) Disabled
110 POP3 (unencrypted) Disabled
143 IMAP (unencrypted) Disabled

Required Secure Settings

Setting Value
Username Your full email address
Password Your email account password
Incoming Server mail.yourdomain.com
IMAP Port 993 (SSL/TLS)
POP3 Port 995 (SSL/TLS)
Outgoing Server mail.yourdomain.com
SMTP Port 465 (SSL/TLS) or 587 (STARTTLS)
Authentication Password (SPA unchecked)

Replace yourdomain.com with your actual domain name.

Email Client Compatibility

TLS 1.2 support depends on both the email client and the operating system.

Microsoft Outlook (Windows)

Outlook Version Windows XP/Vista Windows 7 Windows 8+
2003 or older
2007 ⚠️ Registry fix required
2010 ⚠️ Registry fix required
2013 ⚠️ Registry fix required
2016 or later N/A

Sources:

Apple Mail (macOS)

macOS Version TLS 1.2 Support
10.8 (Mountain Lion) or older ❌ Not supported
10.9 to 10.11 (Mavericks to El Capitan) ⚠️ Partial / Known issues
10.12 (Sierra) or later ✅ Full support

Sources:

iOS (iPhone and iPad)

iOS Version TLS 1.2 Support
iOS 4 or older ❌ Not supported
iOS 5 or later ✅ Supported

Sources:

Android Devices

Android Version TLS 1.2 Support
4.3 (Jelly Bean) or older ❌ Not supported
4.4 (KitKat) ⚠️ App-dependent
5.0 (Lollipop) or later ✅ Full support

Sources:

Alternative Email Clients

For users on older systems, these clients manage their own TLS libraries and support TLS 1.2 independently of the operating system:

Client Platforms Website
Mozilla Thunderbird Windows, macOS, Linux thunderbird.net
eM Client Windows, macOS emclient.com

Frequently Asked Questions

What happens if I don't update my settings before 1 February 2026?

Your email client will no longer be able to connect to our mail servers. You will not be able to send or receive emails until you update to secure settings or upgrade your email client.

I use webmail. Do I need to do anything?

No. Webmail accessed via your browser already uses HTTPS encryption. This change only affects desktop and mobile email clients.

Can I keep using my old email client if I apply the secure settings?

If your email client supports TLS 1.2 (see compatibility tables above), yes. Simply update the port numbers and enable SSL/TLS encryption. If your client does not support TLS 1.2, you will need to upgrade or switch to an alternative client such as Thunderbird.

I'm using Outlook 2010 on Windows 7. What should I do?

You have two options:

  1. Apply the Microsoft registry fix (KB3140245) to enable TLS 1.2 on Windows 7. See the Microsoft source link in the Outlook compatibility section above.
  2. Upgrade to a newer version of Windows and/or Outlook, or switch to an alternative email client like Thunderbird.

Why are insecure ports being disabled?

Unencrypted connections transmit your username, password, and email content in plain text. This makes your data vulnerable to interception and unauthorised access. TLS 1.2 encryption protects your information in transit.

What is the difference between port 465 and port 587?

Port 465 uses implicit TLS, meaning the connection is encrypted from the start. Port 587 uses STARTTLS, where the connection starts unencrypted and then upgrades to TLS. Both are secure when properly configured. Use whichever your email client supports.

I'm a Managed Server customer with legacy systems. Can I request an exception?

Yes. Please contact our support team to discuss your specific requirements. Exceptions may be available for Managed Server customers on a case-by-case basis.

Need Help?

Did you find this article useful?