The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

compliance options email-mta-tls-opportunistic

Prev Next

On Email Security — Server appliances, compliance with FIPS 140-2 and Common Criteria (CC-NDCPP) certification requires that all email delivery use TLS encryption with verification mode. Verification mode requires validation of the next-hop MTA server certificate and the imported certificate authority (CA) before the TLS connection is established. If your environment does not require Common Criteria or FIPS compliance, use this command to enable opportunistic mode instead.

Syntax

[no] compliance options email-mta-tls-opportunistic

Parameters

no

Use the no form of this command to restore email delivery verification mode.

Example

The following example enables opportunistic mode:

hostname (config) # compliance options email-mta-tls-opportunistic

User role

Admin

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Email Security — Server: Release 9.0.