Track and Trace show that Inbound emails are stuck in a Retrying Delivery state with a TLS error message.
or
An outbound mail queue builds on the sending server-side with a TLS error message.
453 TLS Connection Renegotiation failed.
Email Security.cloud
To continue using TLS Business Partners with Enforced encryption, you will need to ensure you are using TLS 1.1 or higher as well as using a SHA2 certificate.
Be aware that the information below is for guidance only. You must retrieve up-to-date information from your mail server vendor to ensure accuracy, for instructions to any other on-premise mail server solution, contact the software vendor.
Warning: Before proceeding with the following steps, ensure your Exchange environment has the latest CU patches installed. Failing to do and continuing to the next steps can negatively affect your mail flow.
To enable TLS 1.2 for both server (inbound) and client (outbound) connections on an Exchange Server, perform the following.
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Client]
"DisabledByDefault"=dword:00000000
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.2\Server]
"DisabledByDefault"=dword:00000000
"Enabled"=dword:00000001
To disable TLS 1.0 for both Server (inbound) and Client (outbound) connections on an Exchange Server perform the following:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.0]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.0\Client]
"DisabledByDefault"=dword:00000001
"Enabled"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.0\Server]
"DisabledByDefault"=dword:00000001
"Enabled"=dword:00000000
To disable TLS 1.1 for both Server (inbound) and Client (outbound) connections on an Exchange Server, perform the following:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.1]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.1\Client]
"DisabledByDefault"=dword:00000001
"Enabled"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.1\Server]
"DisabledByDefault"=dword:00000001
"Enabled"=dword:00000000
For more information about TLS best practices, see the following articles:
Exchange Server TLS guidance, part 1: Getting Ready for TLS 1.2
Exchange Server TLS guidance Part 2: Enabling TLS 1.2 and Identifying Clients Not Using It
Exchange Server TLS guidance Part 3: Turning Off TLS 1.0/1.1