# Heartbeat - monitor email domains

**URL:** https://discuss.elastic.co/t/heartbeat-monitor-email-domains/341306
**Category:** Synthetics
**Created:** [August 21, 2023, 10:08pm UTC](https://discuss.elastic.co/t/heartbeat-monitor-email-domains/341306 "2023-08-21T22:08:38Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![Robin020](https://avatars.discourse-cdn.com/v4/letter/r/71c47a/32.png) [@Robin020](https://discuss.elastic.co/u/Robin020)
#### Post date: [August 21, 2023, 10:08pm UTC](https://discuss.elastic.co/t/heartbeat-monitor-email-domains/341306/1 "2023-08-21T22:08:38Z")

</div>

Hello,

I am trying to monitor email domains (with heartbeat) for example:

```auto
- type: tcp
  name: TLS_CHECK
  schedule: '@every 30s'
  hosts: ["tls://mx.example.com"]
  ports: [25]

```

Unfortantly this give me the following error:  
`tls: first record does not look like a TLS handshake`

What's going wrong?  
When removing the scheme before the host, it works but I don't get the tls certificate which my goal is to monitor.

Hope somebody have suggestions to solve this.

---

<div class="post-metadata">

### Author: ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)
#### Post date: [August 22, 2023, 6:49am UTC](https://discuss.elastic.co/t/heartbeat-monitor-email-domains/341306/2 "2023-08-22T06:49:54Z")

</div>

If you want to use SSL session, there should be a certificate.

```auto
  ssl:
    certificate_authorities: ['/etc/ca.crt']

```

Check [the documentation](https://www.elastic.co/guide/en/beats/heartbeat/current/monitor-tcp-options.html#monitor-tcp-tls-ssl)

---

<div class="post-metadata">

### Author: ![Robin020](https://avatars.discourse-cdn.com/v4/letter/r/71c47a/32.png) [@Robin020](https://discuss.elastic.co/u/Robin020)
#### Post date: [August 22, 2023, 10:40am UTC](https://discuss.elastic.co/t/heartbeat-monitor-email-domains/341306/3 "2023-08-22T10:40:36Z")

</div>

Still get the same error. This is the config:

```auto
- type: tcp
  name: TLS_CHECK
  schedule: '@every 30s'
  hosts: ["smtp.google.com"]
  ports: [25]
  ssl:
    certificate_authorities: ['/etc/heartbeat/ca.crt']
    supported_protocols: ["TLSv1.1", "TLSv1.2"]

```

I have used the ca.crt from the elasticsearch folder (/etc/elasticsearch/certs/http\_ca.crt).

What I am doing wrong here?

---

<div class="post-metadata">

### Author: ![emilioalvap](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/emilioalvap/32/99310_2.png) [@emilioalvap](https://discuss.elastic.co/u/emilioalvap)
#### Post date: [August 22, 2023, 3:13pm UTC](https://discuss.elastic.co/t/heartbeat-monitor-email-domains/341306/4 "2023-08-22T15:13:20Z")

</div>

Hi @Robin020,

`STMP:25` is not a TLS-by-default service, although it can accept TLS negotiation post-fact. Since heartbeat is expecting to get a TLS negotiation handshake, it shows that error when the remote party does not continue with the flow.

You'll need to figure out of your service provides a TLS-secured version on a different port.

---

<div class="post-metadata">

### Author: ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)
#### Post date: [August 22, 2023, 6:50pm UTC](https://discuss.elastic.co/t/heartbeat-monitor-email-domains/341306/5 "2023-08-22T18:50:44Z")

</div>

Good catch Emilio. Standard ports:

- (Gmail) SMTP port (TLS): 587
- (Gmail) SMTP port (SSL): 465

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [September 19, 2023, 6:51pm UTC](https://discuss.elastic.co/t/heartbeat-monitor-email-domains/341306/6 "2023-09-19T18:51:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
