Hi KevinM2, I ran a couple of tests and hopefully the information below is usefully for the email team:
When Connected thru Cox
openssl s_client -connect smtp.cox.net:587 -starttls smtp
CONNECTED(00000003)
depth=2 C = US, O = "Entrust, Inc.", OU = See www.entrust.net/legal-terms, OU = "(c) 2009 Entrust, Inc. - for authorized use only", CN = Entrust Root Certification Authority - G2
verify return:1
depth=1 C = US, O = "Entrust, Inc.", OU = See www.entrust.net/legal-terms, OU = "(c) 2012 Entrust, Inc. - for authorized use only", CN = Entrust Certification Authority - L1K
verify return:1
depth=0 C = US, ST = Georgia, L = Atlanta, O = "Cox Communications, Inc.", CN = smtp.cox.net
verify return:1
---
Certificate chain
0 s:/C=US/ST=Georgia/L=Atlanta/O=Cox Communications, Inc./CN=smtp.cox.net
i:/C=US/O=Entrust, Inc./OU=See www.entrust.net/legal-terms/OU=(c) 2012 Entrust, Inc. - for authorized use only/CN=Entrust Certification Authority - L1K
1 s:/C=US/O=Entrust, Inc./OU=See www.entrust.net/legal-terms/OU=(c) 2012 Entrust, Inc. - for authorized use only/CN=Entrust Certification Authority - L1K
i:/C=US/O=Entrust, Inc./OU=See www.entrust.net/legal-terms/OU=(c) 2009 Entrust, Inc. - for authorized use only/CN=Entrust Root Certification Authority - G2
2 s:/C=US/O=Entrust, Inc./OU=See www.entrust.net/legal-terms/OU=(c) 2009 Entrust, Inc. - for authorized use only/CN=Entrust Root Certification Authority - G2
i:/C=US/O=Entrust, Inc./OU=See www.entrust.net/legal-terms/OU=(c) 2009 Entrust, Inc. - for authorized use only/CN=Entrust Root Certification Authority - G2
---
Server certificate
-----BEGIN CERTIFICATE-----
MIIIfjCCB2agAwIBAgIQDeM8EbsB5IAAAAAAUO+LpDANBgkqhkiG9w0BAQsFADCB
ujELMAkGA1UEBhMCVVMxFjAUBgNVBAoTDUVudHJ1c3QsIEluYy4xKDAmBgNVBAsT
H1NlZSB3d3cuZW50cnVzdC5uZXQvbGVnYWwtdGVybXMxOTA3BgNVBAsTMChjKSAy
MDEyIEVudHJ1c3QsIEluYy4gLSBmb3IgYXV0aG9yaXplZCB1c2Ugb25seTEuMCwG
A1UEAxMlRW50cnVzdCBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eSAtIEwxSzAeFw0x
OTAzMjgxNTU2MTFaFw0yMTA2MjcxNjI2MDlaMGsxCzAJBgNVBAYTAlVTMRAwDgYD
VQQIEwdHZW9yZ2lhMRAwDgYDVQQHEwdBdGxhbnRhMSEwHwYDVQQKExhDb3ggQ29t
bXVuaWNhdGlvbnMsIEluYy4xFTATBgNVBAMTDHNtdHAuY294Lm5ldDCCAiIwDQYJ
KoZIhvcNAQEBBQADggIPADCCAgoCggIBAK/OdNFzu0SiS8ktK2enmnBl5vEqV3gw
3igUpRN4rTcSUrv/MT18rlsnr1zi7XLfi/GkS53mLvxAEKcpU2WduGbgfCO2u/2f
9nkczMzzoN6V3bSWzQyDHG8mK8C79zP4GZqigfcfJ5P79ls9f8MaZW5Po6B5hD/A
l3QWy3K7b2hVe+4XrRb00IPHwETjwvpN36TFPBPLuucWplkF5QiAy6W7r2H+CDps
GYhn4EhJDfODFDS4Xe6E4n1QngHXI6KI9hrKheQPOu1lRLZy5h12gu0k2hXfjlo6
Y20+YR1b1IYdpMH4QoerVaDEkSLqiIrFcBm1xMBanedZmMFCCY+dAAYp8n3K+XKr
Q6vHc9/OzcCollmSIXTfsdaFEmtrpWQZoktBV0G9KdJ0KEHEo4xbyoQcPPoxTG1P
T6Qr3flvEkGrxdctUpJXBdu7RerENaOGbSP6f6Xu6mJzCt7XtMl3I7Yycxtwy2dL
NaIAo08VGsFa32OR2pD8vf9yZFjNkKEu6yR8VaPTzupfXFVoJ1VXCkJSNi1SuB8G
YHIf3ShrnclGeA2ZKnMvkibtyH8ftHxk+u+qZJuzDLRm/Hl/4k2NvfTmTjhY3lLj
zXxh/u0Jhzi8SubgTFww6x5sZla3Jr20mZDVWfVceRiiP74XJR8VwzeHzjDK03DM
6Z30xqcVqZllAgMBAAGjggPMMIIDyDBoBgNVHREEYTBfggxzbXRwLmNveC5uZXSC
EXNtdHAuZWFzdC5jb3gubmV0ghFzbXRwLndlc3QuY294Lm5ldIITc210cG15ZW1h
aWwuY294Lm5ldIIUc210cC5teWVtYWlsLmNveC5uZXQwggH0BgorBgEEAdZ5AgQC
BIIB5ASCAeAB3gB2AId1v+dZfPiMQ5lfvfNu/1aNR1Y2/0q1YMG06v9eoIMPAAAB
acUfi6YAAAQDAEcwRQIhAOUsz9rSN7ruj/n0JyXXWBW5R7GkpOV89fmbnRt0kcIG
AiBAGQxgqbnXM+GQsDiP4p3c8sGTmagS4nuIpxodn5/0bwB2AFWB1MIWkDYBSuoL
m1c8U/DA5Dh4cCUIFy+jqh0HE9MMAAABacUfi7cAAAQDAEcwRQIgSnF2+yxXUfCh
w5p7JKJ1zaohPoTN0DwdOxfPKMExEnsCIQD3CFUYdOJS3V21rxgd+QRhMkZUk243
/s0lAVTkEHxaPAB1AFYUBpov18Ls0/XhvUSyPsdGdrm8mRFcwO+UmFXWidDdAAAB
acUfi/AAAAQDAEYwRAIgArTy+lu821E/gqZaJNcLifaraxV/AbfMPF5NVGJfe4MC
IBdHpQ9bcW833MJUcInq1eBMsqr60mkimm5HnD7jRoI7AHUAu9nfvB+KcbWTlCOX
qpJ7RzhXlQqrUugakJZkNo4e0YUAAAFpxR+LywAABAMARjBEAiB86dhDkHnp6kbm
pyfvycx7v9tcG8n9rEsYOuu2zWLuMwIgHIcLBZswOMF1b+0+dcWXRtd3X6CcBZN1
sK3e+yVMvocwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggr
BgEFBQcDAjAzBgNVHR8ELDAqMCigJqAkhiJodHRwOi8vY3JsLmVudHJ1c3QubmV0
L2xldmVsMWsuY3JsMEsGA1UdIAREMEIwNgYKYIZIAYb6bAoBBTAoMCYGCCsGAQUF
BwIBFhpodHRwOi8vd3d3LmVudHJ1c3QubmV0L3JwYTAIBgZngQwBAgIwaAYIKwYB
BQUHAQEEXDBaMCMGCCsGAQUFBzABhhdodHRwOi8vb2NzcC5lbnRydXN0Lm5ldDAz
BggrBgEFBQcwAoYnaHR0cDovL2FpYS5lbnRydXN0Lm5ldC9sMWstY2hhaW4yNTYu
Y2VyMB8GA1UdIwQYMBaAFIKicHTdvFM/z3vU981/p2DGCky/MB0GA1UdDgQWBBRp
IkU06SvKSH+CGfcEJzHjZLYOvDAJBgNVHRMEAjAAMA0GCSqGSIb3DQEBCwUAA4IB
AQBsTm8k1uE7mN1shRiYm8SXSoGKJDnDHGTCbabQV8RGBOZzNumUI1e3J+ERIkbc
B8uu7vLQN+EaWkysRLjBwjAheRGGjir16xvO2H8dN2ZBrKzKAZRTFJHeYOggYQ9D
FSjOqg+LdiKAVoG6ffQ7KnvojS4bXiArA2uHgjIuWjQuI9YHtsL8MBrvQl3QNzMs
TwDIJmVYfqSC4UGA3An7NzQAwYxpBh+l1OVniusZsX/1pvIWe7uudXdN54u/3J2L
DnLrfJ2yDGcm4sHMtFlwkWzJTrjboTkuc8NFnqo6Fqrkeo10RBkjGWkdk7QJJVgV
Tfkoa6DLd8lIqn6rOaaeSqNO
-----END CERTIFICATE-----
subject=/C=US/ST=Georgia/L=Atlanta/O=Cox Communications, Inc./CN=smtp.cox.net
issuer=/C=US/O=Entrust, Inc./OU=See www.entrust.net/legal-terms/OU=(c) 2012 Entrust, Inc. - for authorized use only/CN=Entrust Certification Authority - L1K
---
No client certificate CA names sent
Peer signing digest: SHA512
Server Temp Key: ECDH, P-256, 256 bits
---
SSL handshake has read 5740 bytes and written 468 bytes
---
New, TLSv1/SSLv3, Cipher is ECDHE-RSA-AES256-GCM-SHA384
Server public key is 4096 bit
Secure Renegotiation IS supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
SSL-Session:
Protocol : TLSv1.2
Cipher : ECDHE-RSA-AES256-GCM-SHA384
Session-ID: 75C05C390171A1DE8E99FD83C512A226CBC13FCC653677CEE473D5EAD664008F
Session-ID-ctx:
Master-Key: BC3A30B7D2E71F97A178ECD5630366310736CE4154B7E41CAE6D8844CE1329BA6BB32F1DAD9F77B4DBB2B49A7A3785EF
Key-Arg : None
PSK identity: None
PSK identity hint: None
SRP username: None
TLS session ticket lifetime hint: 300 (seconds)
TLS session ticket:
0000 - e3 cc f0 35 86 5b ab 52-16 7d 22 42 3b 35 e6 41 ...5.[.R.}"B;5.A
0010 - 45 d7 d7 c6 3c bf 97 72-75 91 37 2a 2c a0 c9 cb E...<..ru.7*,...
0020 - 86 44 7e 5a 3e a4 d2 c8-01 1b 37 e0 ba 68 68 c2 .D~Z>.....7..hh.
0030 - 2d 7a ac e9 3d 66 81 01-39 93 a3 98 71 96 ac d8 -z..=f..9...q...
0040 - ff 86 f0 29 dc 7c d9 13-9d b7 98 97 e9 a0 af f0 ...).|..........
0050 - 34 07 f4 0f 25 c7 05 62-f1 f0 b4 81 ba 18 8b de 4...%..b........
0060 - 4f be 26 d1 b7 27 65 de-6c 4f 32 bf f8 3c 96 13 O.&..'e.lO2..<..
0070 - 4f db 6f af 53 f0 9c e1-00 46 ee be d7 fc a0 cd O.o.S....F......
0080 - 60 21 b9 34 13 35 dc 34-53 29 1d 42 a8 8e c7 5a `!.4.5.4S).B...Z
0090 - 8e 9a 7a 85 41 84 fb c8-87 9c 5c 8b 91 5d bc 6f ..z.A.....\..].o
Start Time: 1556492232
Timeout : 300 (sec)
Verify return code: 0 (ok)
---
250 OK
read:errno=0
When Connected thru T-Mobile
openssl s_client -connect smtp.cox.net:587 -starttls smtp
CONNECTED(00000003)
didn't found starttls in server response, try anyway...
4531119724:error:140790E5:SSL routines:ssl23_write:ssl handshake failure:s23_lib.c:177:
---
no peer certificate available
---
No client certificate CA names sent
---
SSL handshake has read 198 bytes and written 342 bytes
---
New, (NONE), Cipher is (NONE)
Secure Renegotiation IS NOT supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
SSL-Session:
Protocol : TLSv1.2
Cipher : 0000
Session-ID:
Session-ID-ctx:
Master-Key:
Key-Arg : None
PSK identity: None
PSK identity hint: None
SRP username: None
Start Time: 1556492436
Timeout : 300 (sec)
Verify return code: 0 (ok)
---