What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
If you see STARTTLS failed: SSL connect attempt failed with OpenSSL error 1416F086, the key clue is usually the accompanying text: certificate verify failed. That means the client reached the SMTP server but rejected its TLS certificate. The cause may be an incomplete server certificate chain, a missing or outdated client CA bundle, a hostname mismatch, an incorrect clock, or a TLS-inspecting proxy—not necessarily a bad SMTP password.
Test the exact server name, port, and encryption mode first. Then use the verification result to decide whether to fix the server certificate or the trust store used by your application. Keep certificate verification enabled; bypassing it can expose credentials and email to interception.
What the error means
SMTP STARTTLS upgrades a connection from plaintext to TLS. Typically, the client connects, sends EHLO, receives the server’s advertised capabilities, issues STARTTLS, and begins the TLS handshake. During that handshake, the client checks whether the server certificate is trusted, valid for the requested hostname, and within its validity dates.
When the expanded error says tls_process_server_certificate:certificate verify failed, TLS reached certificate validation and the client rejected what it received. In most cases this happens before SMTP authentication, so changing a password or generating an app password will not fix a certificate-verification failure. The number 1416F086 by itself is not a complete diagnosis; read the full OpenSSL message and verification result.
#1 Best Overall
- 𝐇𝐢𝐠𝐡-𝐒𝐩𝐞𝐞𝐝 𝐔𝐒𝐁 𝐄𝐭𝐡𝐞𝐫𝐧𝐞𝐭 𝐀𝐝𝐚𝐩𝐭𝐞𝐫 - UE306 is a USB 3.0 Type-A to RJ45 Ethernet adapter that adds a reliable wired network port to your laptop, tablet, or Ultrabook. It delivers fast and stable 10/100/1000 Mbps wired connections to your computer or tablet via a router or network switch, making it ideal for file transfers, HD video streaming, online gaming, and video conferencing.
- 𝐔𝐒𝐁 𝟑.𝟎 𝐟𝐨𝐫 𝐅𝐚𝐬𝐭𝐞𝐫, 𝐌𝐨𝐫𝐞 𝐒𝐭𝐚𝐛𝐥𝐞 𝐃𝐚𝐭𝐚 𝐓𝐫𝐚𝐧𝐬𝐟𝐞𝐫𝐬- Powered via USB 3.0, this adapter provides high-speed Gigabit Ethernet without the need for external power(10/100/1000Mbps). Backward compatible with USB 2.0/1.1, it ensures reliable performance across a wide range of devices.
- 𝐒𝐮𝐩𝐩𝐨𝐫𝐭𝐬 𝐍𝐢𝐧𝐭𝐞𝐧𝐝𝐨 𝐒𝐰𝐢𝐭𝐜𝐡- Easily connect your Nintendo Switch to a wired network for faster downloads and a more stable online gaming experience compared to Wi-Fi.
- 𝐏𝐥𝐮𝐠 𝐚𝐧𝐝 𝐏𝐥𝐚𝐲- No driver required for Nintendo Switch, Windows 11/10/8.1/8, and Linux. Simply connect and enjoy instant wired internet access without complicated setup.
- 𝐁𝐫𝐨𝐚𝐝 𝐃𝐞𝐯𝐢𝐜𝐞 𝐂𝐨𝐦𝐩𝐚𝐭𝐢𝐛𝐢𝐥𝐢𝐭𝐲- Supports Nintendo Switch, PCs, laptops, Ultrabooks, tablets, and other USB-powered web devices; works with network equipment including modems, routers, and switches.
This OpenSSL verification error is not unique to SMTP or STARTTLS. Similar failures can occur with HTTPS and other TLS clients. A reported Git send-email case, for example, included the more useful detail certificate verify failed.
1. Confirm the SMTP port and encryption mode
Use the exact combination documented by your mail provider. These are common conventions, not guarantees:
| Port | Usual mode | What happens |
|---|---|---|
| 25 | SMTP, often with optional STARTTLS | Common for server-to-server delivery; often restricted for client submission. |
| 587 | SMTP submission with STARTTLS | A common choice for authenticated application or user mail submission. |
| 465 | Implicit TLS | TLS begins immediately; do not configure SMTP STARTTLS on this port. |
Older software may label encryption options “TLS” or “SSL” inconsistently. Some use “TLS” for STARTTLS; others use it for implicit TLS. Follow the provider’s documented settings rather than relying on a label. A wrong mode can fail before authentication.
Recommended Free Tools
2. Test the exact endpoint with OpenSSL
For STARTTLS on port 587, substitute the hostname and port you actually configured:
openssl s_client
-starttls smtp
-connect smtp.example.com:587
-servername smtp.example.com
-showcerts
-verify_return_error
For implicit TLS on port 465, omit -starttls smtp:
openssl s_client
-connect smtp.example.com:465
-servername smtp.example.com
-showcerts
-verify_return_error
The -servername value should be the DNS hostname the application is meant to contact. It sends SNI, which can matter when a server hosts multiple TLS names. Use the hostname, not just the server’s IP address, unless the certificate is specifically valid for that IP.
Look near the end of the output for Verify return code: 0 (ok). A nonzero code such as 20 (unable to get local issuer certificate) or 21 (unable to verify the first certificate) points to a trust or chain problem. Inspect the certificate subjects and issuers, validity dates, and Subject Alternative Name (SAN) entries as well. OpenSSL’s s_client documentation describes the available connection and verification options.
Rank #2
- Connects a USB 3.0 device (computer/laptop) to a router, modem, or network switch to deliver Gigabit Ethernet to your network connection. Does not support Smart TV or gaming consoles (e.g.Nintendo Switch).
- Supported features include Wake-on-LAN function, Green Ethernet & IEEE 802.3az-2010 (Energy Efficient Ethernet)
- Supports IPv4/IPv6 pack Checksum Offload Engine (COE) to reduce Cental Processing Unit (CPU) loading
- Compatible with Windows 8.1 or higher, Mac OS
A successful TCP connection alone is not enough: it does not prove that TLS negotiation, certificate verification, SMTP authentication, or message submission will work. For a simple reachability check, you can use nc -vz smtp.example.com 587, but use the OpenSSL test to investigate TLS.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →3. Match the failure to the likely cause
| OpenSSL result or clue | Likely cause | Next step |
|---|---|---|
unable to get local issuer certificate |
The server may omit an intermediate certificate, the client may lack a required CA, or the application may be using the wrong trust path. | Inspect the certificates returned by the server; then check the system and application trust stores. |
unable to verify the first certificate |
Often an incomplete chain or an issuer the client does not trust. | Check the server’s intermediate chain and the client’s CA bundle. |
| Hostname mismatch | The configured name is not covered by the certificate’s SAN, or the client is connecting by IP or to the wrong service name. | Use the provider’s correct SMTP hostname or install a certificate that covers the configured name. |
| Expired or not-yet-valid certificate | The leaf or an intermediate certificate is outside its validity window; the local clock could also be wrong. | Check certificate dates and UTC time; renew or replace the affected certificate if needed. |
| Self-signed or unknown issuer | The service uses a private CA or an untrusted self-signed certificate. | Obtain and trust the approved private CA, or replace the certificate with one chaining to a trusted CA. |
| OpenSSL verifies successfully, but the application fails | The application may use another CA bundle, hostname, endpoint, runtime, or network route. | Compare the application’s settings and trust store with the successful test. |
4. Check the hostname, DNS, and endpoint
The SMTP submission hostname is not necessarily the domain’s MX hostname. Use the provider’s documented submission name; do not assume that an MX record, web-server name, or IP address is interchangeable with it.
getent hosts smtp.example.com
dig +short smtp.example.com
Compare the resolved addresses with the endpoint you intended to test. If the hostname resolves to several servers, or has both IPv4 and IPv6 addresses, different backends or routes may present different certificates. If the failure is intermittent, test each relevant endpoint where practical and compare the certificate issuer, SAN, and chain. A load balancer or mail cluster may have one node configured incorrectly.
5. Check the system clock
A certificate can appear expired or not yet valid when the client clock is substantially wrong. Check the system’s UTC time and synchronization status:
date -u
timedatectl status
If time synchronization is disabled and the system uses systemd’s time service, sudo timedatectl set-ntp true may enable it. Time-management tools vary by operating system and environment. Avoid setting a production system’s clock manually without considering effects on logs, authentication, scheduled jobs, and databases.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →6. Repair the client CA bundle if it is missing or damaged
If OpenSSL reports an issuer or trust-store problem, update or reinstall the operating system’s CA certificates and refresh the trust database. Commands vary by distribution.
Rank #3
- COMPACT DESIGN - The compact-designed portable BENFEI USB A/C to Ethernet adapter connects your computer or tablet to a router,modem or network switch for network connection. It adds a standard RJ45 port to your Ultrabook, notebook or Macbook Air for file transferring, video conferencing, gaming, and HD video streaming.
- SUPERIOR STABILITY - Built-in advanced IC chip works as the bridge between RJ45 Ethernet cable and your USB A/C devices. The driver-free installation with native driver support in Chrome, Mac, and Windows OS; The USB A/C Ethernet adapter dongle supports important performance features including Wake-on-Lan (WoL), Full-Duplex (FDX) and Half-Duplex (HDX) Ethernet, Crossover Detection, Backpressure Routing, Auto-Correction (Auto MDIX).
- INCREDIBLE PERFORMANCE - Supports full 10/100/1000Mbps gigabit ethernet performance over USB A/C's 5Gbps bus, faster and more reliable than most wireless connections. Link and Activity LEDs. USB powered, no external power required. Backward compatible with USB 2.0/1.1.✅ To reach 1Gbps, make sure to use CAT6 & up Ethernet cables.
- BROAD COMPATIBILITY - The USB A/C-Ethernet adapter is compatible with Windows 11/10/8.1/8/7/Vista/XP, Mac OSX 10.6/10.7/10.8/10.9/10.10/10.11/10.12, Linux kernel 3.x/2.6, Android and Chrome OS.Compatible with IEEE 802.3, IEEE 802.3u and IEEE 802.3ab. Supports IEEE 802.3az (Energy Efficient Ethernet).❌Do Not Support Windows RT. (NOT compatible with Nintendo Switch.)
- 18 MONTH WARRANTY - Exclusive BENFEI Unconditional 18-month Warranty ensures long-time satisfaction of your purchase; Friendly and easy-to-reach customer service to solve your problems timely.
Debian and Ubuntu
sudo apt-get update
sudo apt-get install --reinstall ca-certificates
sudo update-ca-certificates
RHEL, CentOS Stream, Rocky Linux, AlmaLinux, and Fedora
sudo dnf reinstall ca-certificates
sudo update-ca-trust
Older systems may use yum instead of dnf. After the repair, repeat the OpenSSL test and then retry the application. Reinstalling CA certificates is a common fix, not a guarantee: it will not correct a wrong hostname or an incomplete chain on your SMTP server.
On cPanel systems, damaged or missing CA files can also cause misleading license-expiration symptoms when the server cannot make a trusted connection to refresh its license. cPanel’s documented guidance includes backing up /etc/pki, reinstalling ca-certificates using the system’s package manager, and refreshing the license with /usr/local/cpanel/cpkeyclt. Follow the support procedure for your installation; an apparent license error may be a secondary TLS symptom rather than an actually expired license.
7. Check the server’s certificate chain
With -showcerts, OpenSSL displays the certificates sent by the SMTP server. Check that the leaf certificate is for the hostname you use and that its issuer links through the necessary intermediate certificates. Browsers can sometimes mask a missing intermediate because they have cached it or can retrieve it; a command-line mail client may not.
If you administer the server, configure the mail service with the leaf certificate and required intermediate bundle (often called the full chain or certificate bundle), and make sure the private key matches the leaf certificate. Reload or restart the mail service as required, then test from outside the server and against every advertised submission hostname. A web server and mail daemon can use separate TLS configurations, so a valid website certificate does not prove SMTP is configured correctly.
The server normally should not send the root CA as part of the chain. If you do not administer the SMTP server, give its operator the hostname, port, time of the test, and verification error so they can check the chain presented by the service.
8. Check the trust store used by the application
A successful OpenSSL command proves that the tested OpenSSL binary can validate the tested endpoint using its trust path. It does not prove that Git, Perl, Python, Java, PHP, a control panel, or a container uses the same certificates.
Rank #4
- Dual USB-A/C Port Design: This USB hub with ethernet adapter features dual connectors for both USB C and USB A devices, ensuring wide compatibility across laptops, tablets, and smartphones. It includes 1x Gigabit Ethernet port and 3x USB A 3.0 ports, all usable at the same time for smooth and efficient connectivity. 📌Note: When using USB-A to connect devices, please ensure the USB-C is securely attached to the USB-A connector.
- Stable Gigabit Ethernet Adapter: Get fast, wired Internet up to 1000Mbps with this USB C to ethernet adapter. Backward compatible with 10/100Mbps networks for flexible connectivity across various setups. Ideal for streaming, gaming, and large file transfers. 📌Note: Ensure the RJ45 connector is plugged in securely in the port and use CAT6 & above Ethernet cable is required to reach 1 Gbps.
- 5Gbps Data Transfer: Transfer large files, photos, and videos in seconds with this USB 3.0 hub supporting speeds up to 5Gbps—10× faster than USB 2.0. Backward compatible with USB 2.0 and 1.1 devices, this USB splitter expands one port into three for connecting keyboards, mice, and flash drives for everyday use. 📌Note: The three USB-A 3.0 ports share a total 5Gbps bandwidth.【NO HDMI port, NO USB-C data port, and NO PD charging】
- Plug and Play: Reliable USB to ethernet adapter ready to use in seconds. Instantly connects with USB-A and USB-C devices including MacBook Pro/Air, iPad Pro, iMac, Surface Laptops, Chromebook, XPS, tablets, Steam, and smartphones. Works with Windows, macOS, Linux, Chrome OS, and Android. 📌XP/Win7 may need driver. Older systems may not recognize this product due to its USB 3.0 chip. Please refer to the “Installation Manual” to manually download and install the driver.
- Durable & Portable Build: Made with sturdy aluminum alloy, this RJ45 to USB-C adapter delivers long-term durability, efficient heat dissipation, and stable performance for offices, corporate deployments, classrooms, and campus workstations—while its slim, portable form factor makes it ideal for business travel, educators, and mobile professionals.
Common differences include Python’s certifi bundle, Java’s cacerts, a bundled Perl/OpenSSL runtime, PHP’s configured CA path, a minimal container with no current CA package, or environment variables that override defaults. Check the OpenSSL build and relevant environment variables:
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsopenssl version -a
openssl version -d
env | grep -E 'SSL_CERT|REQUESTS_CA_BUNDLE|CURL_CA_BUNDLE'
For a Perl application using IO::Socket::SSL, check which module is installed and consult its documentation for trust-store configuration:
perl -MIO::Socket::SSL -e 'print "$IO::Socket::SSL::VERSIONn"'
perldoc IO::Socket::SSL
An application can also connect to a different hostname or IP than your manual test. Compare its actual SMTP host, port, encryption setting, runtime, CA path, and route. A case discussed in Red Hat’s IO::Socket::SSL tracker illustrates that application-specific CA behavior can matter.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.9. Investigate private CAs and TLS inspection
If the certificate issuer is an organization’s internal CA, a corporate firewall, antivirus product, security gateway, hosting layer, or outbound proxy may be intercepting TLS and issuing a replacement certificate. The browser may trust that internal CA while the mail application does not. Compare the issuer and certificate from a managed network with the result from another network, if your organization permits it.
For an intentionally private SMTP service, obtain the CA certificate through a trusted administrative channel, install it in the operating system or the application’s trust store, and retest. Confirm that the certificate covers the SMTP hostname and has a valid chain. Do not download a purported CA certificate from an arbitrary source or trust a certificate merely because it makes the error disappear. If a managed proxy is responsible, use your organization’s approved CA setup or an approved non-intercepted route.
Free tools Windows power users keep installed
One-click scans. No signup required.
10. If this is Git send-email
For a provider that documents port 587 with STARTTLS, a typical Git configuration is:
Best Value
- [Expansion Ports] The USB C to Ethernet Adapter expands the device to three USB 3.0 ports and one Gigabit Ethernet port. Provides you more peripheral ports while maintaining a stable network connection, plug and play, no driver required.
- [Gigabit Network Port] ALL-LUCKY USB Ethernet Adapter transmission rate up to 1000Mbps, also compatible with 10/100Mbps bandwidth. It allows you to enjoy a smooth and stable network connection and avoid too much lag. (Note: To reach 1Gbps, please use CAT6 or above Ethernet cable connection)
- [Convertible Connector]This usb hub with ethernet not only has USB-A connector, but also can be converted to USB-C connector, so that you can easily convert the connector according to the device port, improve the convenience of use.
- [High-Speed Data Transfer] The usb to ethernet adapter adopts USB 3.0 transmission technology, supports up to 5Gbps transmission rate, and is compatible with USB 2.0(480Gbps),USB 1.0(12Mbps), easily transfer video, files and other data for you in seconds. (Note: Maximum output current is 900mA, does not support charging devices.)
- [Widely Compatible]The usb c ethernet adapter for iMac, MacBook Pro, iPad Pro, XPS and many other devices. Compatible with Windows 11/10/8.1/8, Mac OS, iPad OS, Chrome OS.(Note: Driver is required on Win 7) It can be used in office, school, library and other occasions, compact and portable, easy to carry around.
git config --global sendemail.smtpserver smtp.example.com
git config --global sendemail.smtpserverport 587
git config --global sendemail.smtpencryption tls
git config --global sendemail.smtpuser [email protected]
Use the actual hostname, account, and settings required by your provider. Then enable SMTP diagnostic output for a test:
git send-email --smtp-debug=1 ...
Consult the Git send-email documentation for supported configuration names and behavior. Debug output can contain addresses or other sensitive details, so review it before sharing it. If the OpenSSL test succeeds but Git still fails, investigate Git’s runtime and trust configuration rather than assuming the SMTP server or password is at fault.
11. Retest the SMTP conversation without sending credentials
For STARTTLS, you can establish a test session and inspect the SMTP capabilities after TLS begins:
openssl s_client
-starttls smtp
-connect smtp.example.com:587
-servername smtp.example.com
-crlf
After TLS is established, type EHLO test.example. You should receive SMTP capability lines. Do not enter a real password in an interactive session unless you understand the authentication mechanism and risks. This test can confirm that the SMTP conversation proceeds, but it does not substitute for verifying the certificate. For details on s_client and verification behavior, see the OpenSSL documentation and its certificate verification options.
Keep certificate verification enabled
Do not treat --insecure, a library verify mode set to “NONE,” or accepting any certificate as a fix. Those settings suppress the check rather than repair the cause, and can allow an impostor to capture SMTP credentials or read mail traffic. Likewise, changing the configured hostname to force a match weakens the meaning of the certificate check. A bypass, if used at all, belongs only in a controlled diagnostic comparison and must be reverted immediately—not in production.
Quick workflow
- Copy the complete error, especially the text after the OpenSSL code.
- Confirm the provider’s hostname, port, and mode: STARTTLS or implicit TLS.
- Run the matching
openssl s_clienttest with the exact hostname and-servername. - If verification fails, use the return code, SAN, issuer, and validity dates to distinguish a hostname, chain, trust-store, or time problem.
- If OpenSSL succeeds but the application fails, compare its runtime, CA bundle, hostname, endpoint, and network route.
- Make the correction and retest with verification enabled. Investigate credentials or provider policy only after TLS validation succeeds.
A certificate-verification failure does not by itself show that a remote service blocked your IP. For example, a Let’s Encrypt community case distinguishes reaching a service from failing local certificate verification. Similarly, the same broad OpenSSL failure can arise in other TLS applications, including LDAPS; see this Proxmox discussion for an application-specific example.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

