After updating to 2025-09b I encounter problems with outgoing messages from Mailcow to Gmail . I thought it is the same as https://community.mailcow.email/d/5368-tls-is-required-but-was-not-offered-by-host-gmail-smtp-inlgooglecom
because the workaround works, but the openssl test seems to be ok:
root@mail:~# openssl s_client -connect gmail-smtp-in.l.google.com:25 -starttls smtp
CONNECTED(00000003)
depth=2 C = US, O = Google Trust Services LLC, CN = GTS Root R1
verify return:1
depth=1 C = US, O = Google Trust Services, CN = WR2
verify return:1
depth=0 CN = mx.google.com
verify return:1
---
Certificate chain
0 s:CN = mx.google.com
i:C = US, O = Google Trust Services, CN = WR2
a:PKEY: id-ecPublicKey, 256 (bit); sigalg: RSA-SHA256
v:NotBefore: Sep 8 08:36:45 2025 GMT; NotAfter: Dec 1 08:36:44 2025 GMT
1 s:C = US, O = Google Trust Services, CN = WR2
i:C = US, O = Google Trust Services LLC, CN = GTS Root R1
a:PKEY: rsaEncryption, 2048 (bit); sigalg: RSA-SHA256
v:NotBefore: Dec 13 09:00:00 2023 GMT; NotAfter: Feb 20 14:00:00 2029 GMT
2 s:C = US, O = Google Trust Services LLC, CN = GTS Root R1
i:C = BE, O = GlobalSign nv-sa, OU = Root CA, CN = GlobalSign Root CA
a:PKEY: rsaEncryption, 4096 (bit); sigalg: RSA-SHA256
v:NotBefore: Jun 19 00:00:42 2020 GMT; NotAfter: Jan 28 00:00:42 2028 GMT
---
Server certificate
-----BEGIN CERTIFICATE-----
MIIGwzCCBaugAwIBAgIQYVoXtaYWj/4K6o5W8l9teTANBgkqhkiG9w0BAQsFADA7
MQswCQYDVQQGEwJVUzEeMBwGA1UEChMVR29vZ2xlIFRydXN0IFNlcnZpY2VzMQww
CgYDVQQDEwNXUjIwHhcNMjUwOTA4MDgzNjQ1WhcNMjUxMjAxMDgzNjQ0WjAYMRYw
FAYDVQQDEw1teC5nb29nbGUuY29tMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE
Y/FjULTybCARlUlPc7xsOkYV/GUVtV7+/oBJ+C0Y0uZjD4P3kAODHW+04lfiuDNy
gra52hoOQ3RNHIZ182aHoaOCBK8wggSrMA4GA1UdDwEB/wQEAwIHgDATBgNVHSUE
DDAKBggrBgEFBQcDATAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBTB46l4kO164Q5t
B59vqbG3+jHGaTAfBgNVHSMEGDAWgBTeGx7teRXUPjckwyG77DQ5bUKyMDBYBggr
BgEFBQcBAQRMMEowIQYIKwYBBQUHMAGGFWh0dHA6Ly9vLnBraS5nb29nL3dyMjAl
BggrBgEFBQcwAoYZaHR0cDovL2kucGtpLmdvb2cvd3IyLmNydDCCAoYGA1UdEQSC
An0wggJ5gg1teC5nb29nbGUuY29tgg9zbXRwLmdvb2dsZS5jb22CEmFzcG14Lmwu
Z29vZ2xlLmNvbYIXYWx0MS5hc3BteC5sLmdvb2dsZS5jb22CF2FsdDIuYXNwbXgu
bC5nb29nbGUuY29tghdhbHQzLmFzcG14LmwuZ29vZ2xlLmNvbYIXYWx0NC5hc3Bt
eC5sLmdvb2dsZS5jb22CGmdtYWlsLXNtdHAtaW4ubC5nb29nbGUuY29tgh9hbHQx
LmdtYWlsLXNtdHAtaW4ubC5nb29nbGUuY29tgh9hbHQyLmdtYWlsLXNtdHAtaW4u
bC5nb29nbGUuY29tgh9hbHQzLmdtYWlsLXNtdHAtaW4ubC5nb29nbGUuY29tgh9h
bHQ0LmdtYWlsLXNtdHAtaW4ubC5nb29nbGUuY29tghhnbXItc210cC1pbi5sLmdv
b2dsZS5jb22CHWFsdDEuZ21yLXNtdHAtaW4ubC5nb29nbGUuY29tgh1hbHQyLmdt
ci1zbXRwLWluLmwuZ29vZ2xlLmNvbYIdYWx0My5nbXItc210cC1pbi5sLmdvb2ds
ZS5jb22CHWFsdDQuZ21yLXNtdHAtaW4ubC5nb29nbGUuY29tgg1teDEuc210cC5n
b29ngg1teDIuc210cC5nb29ngg1teDMuc210cC5nb29ngg1teDQuc210cC5nb29n
ghVhc3BteDIuZ29vZ2xlbWFpbC5jb22CFWFzcG14My5nb29nbGVtYWlsLmNvbYIV
YXNwbXg0Lmdvb2dsZW1haWwuY29tghVhc3BteDUuZ29vZ2xlbWFpbC5jb22CEWdt
ci1teC5nb29nbGUuY29tMBMGA1UdIAQMMAowCAYGZ4EMAQIBMDYGA1UdHwQvMC0w
K6ApoCeGJWh0dHA6Ly9jLnBraS5nb29nL3dyMi85VVZiTjB3NUU2WS5jcmwwggED
BgorBgEEAdZ5AgQCBIH0BIHxAO8AdQDM+w9qhXEJZf6Vm1PO6bJ8IumFXA2Xjbap
flTA/kwNsAAAAZkor2JTAAAEAwBGMEQCIBFM0TvhDHKTZ7TCs09Kd1dytG9KnMFA
I0/UcZs5R0YcAiBYI/rmxtCiOPoqtu5yT6GQJ/4hH0GCgPS1w2ct07jXbgB2AN3c
yjSV1+EWBeeVMvrHn/g9HFDf2wA6FBJ2Ciysu8gqAAABmSivYkwAAAQDAEcwRQIh
AJVIHnpjFHR8kYLAodTcEBHKcNX9bu3f9xlfV4imLc1LAiB6lV0AxYFAvcfcWMr2
G04meUTYiYRzWoqmu039Q0R1+DANBgkqhkiG9w0BAQsFAAOCAQEAnVIWFNGnu/ck
5kuA8BuXgM+uEzWS0SupstB+PahL5V7W66S1umORk1DEl7r9EK24tobgcaVFPotB
H8Y80Ez2CyCe6KI4MNu1qfiRlpVMuK3A06X4SpAAvTrnQq+UwsB5wwq94KPP5NXZ
aDD0bDOgDeMDVC6vUwEBr10nPhva5K9IrqWLPJ28+MUqZtvjoEUBACpBEElYPirl
lUlDaVVgH6xk17nY1CInE78fhdxjwZdmRrWl6eqmkJpbJYOIG6n+iCNejOmu6jnV
KbsvGdd1O+0FT4Iayi62zKD7L0/761Zw2O1POSKnG38Ylryf07twAKj9gg6hwNX9
nJZf8AK27Q==
-----END CERTIFICATE-----
subject=CN = mx.google.com
issuer=C = US, O = Google Trust Services, CN = WR2
---
No client certificate CA names sent
Peer signing digest: SHA256
Peer signature type: ECDSA
Server Temp Key: X25519, 253 bits
---
SSL handshake has read 5000 bytes and written 445 bytes
Verification: OK
---
New, TLSv1.3, Cipher is TLS_AES_256_GCM_SHA384
Server public key is 256 bit
Secure Renegotiation IS NOT supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
Early data was not sent
Verify return code: 0 (ok)
---
250 SMTPUTF8
I have these messages in the UI:
09/22/2025, 05:53:52 PM warning warning: TLS policy lookup for gmail.com/alt4.gmail-smtp-in.l.google.com: client TLS configuration problem
09/22/2025, 05:53:52 PM warning warning: smtp_tls_policy_maps, next-hop destination "gmail.com": policy table lookup error
09/22/2025, 05:53:52 PM warning warning: socketmap:inet:postfix-tlspol:8642:QUERY lookup error for "gmail.com"
09/22/2025, 05:53:52 PM warning warning: table socketmap:inet:postfix-tlspol:8642:QUERY lookup error: time limit exceeded
09/22/2025, 05:53:52 PM warning warning: TLS policy lookup for gmail.com/alt3.gmail-smtp-in.l.google.com: client TLS configuration problem
09/22/2025, 05:53:52 PM warning warning: smtp_tls_policy_maps, next-hop destination "gmail.com": policy table lookup error
09/22/2025, 05:53:52 PM warning warning: socketmap:inet:postfix-tlspol:8642:QUERY lookup error for "gmail.com"
09/22/2025, 05:53:52 PM warning warning: table socketmap:inet:postfix-tlspol:8642:QUERY lookup error: time limit exceeded
09/22/2025, 05:53:52 PM warning warning: TLS policy lookup for gmail.com/alt2.gmail-smtp-in.l.google.com: client TLS configuration problem
09/22/2025, 05:53:52 PM warning warning: smtp_tls_policy_maps, next-hop destination "gmail.com": policy table lookup error
09/22/2025, 05:53:52 PM warning warning: socketmap:inet:postfix-tlspol:8642:QUERY lookup error for "gmail.com"
09/22/2025, 05:53:52 PM warning warning: table socketmap:inet:postfix-tlspol:8642:QUERY lookup error: time limit exceeded
09/22/2025, 05:53:52 PM warning warning: TLS policy lookup for gmail.com/alt1.gmail-smtp-in.l.google.com: client TLS configuration problem
09/22/2025, 05:53:52 PM warning warning: smtp_tls_policy_maps, next-hop destination "gmail.com": policy table lookup error
09/22/2025, 05:53:52 PM warning warning: socketmap:inet:postfix-tlspol:8642:QUERY lookup error for "gmail.com"
09/22/2025, 05:53:52 PM warning warning: table socketmap:inet:postfix-tlspol:8642:QUERY lookup error: time limit exceeded
09/22/2025, 05:53:52 PM warning warning: TLS policy lookup for gmail.com/gmail-smtp-in.l.google.com: client TLS configuration problem
09/22/2025, 05:53:52 PM warning warning: smtp_tls_policy_maps, next-hop destination "gmail.com": policy table lookup error
09/22/2025, 05:53:52 PM warning warning: socketmap:inet:postfix-tlspol:8642:QUERY lookup error for "gmail.com"
09/22/2025, 05:53:52 PM warning warning: table socketmap:inet:postfix-tlspol:8642:QUERY lookup error: time limit exceeded
and these in the mailcowdockerized-postfix-mailcow-1.log
How to troubleshoot further?