Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    How are you supposed to set up Email notifications?

    Scheduled Pinned Locked Moved General pfSense Questions
    11 Posts 4 Posters 440 Views 5 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D Offline
      dhpo5683
      last edited by

      Under System > Advanced > Notifications

      I'm attempting to set up Email notifications so I can receive a confirmation email to set up an ACME certificate. I have been trying for a whole day, and I'm becoming incredibly frustrated, since literally nothing I have done has worked.

      First, I set up SMTP via ProtonMail. I already have a domain, and on Proton's end everything is set up correctly. The credentials I have are all valid. I have used the port they recommend: 587 and an alternative 465 when that didn't work. I keep getting the error Error: Failed to connect to ssl://smtp.protonmail.ch:567 [SMTP: Failed to connect socket: Operation timed out (code: -1, response: )] whenever I check the Secure SMTP Connection and/or Validate SSL/TLS boxes.

      I also attempted this with Google's SMTP. Once again, these credentials are all valid, but I still can't find any success. With this, I continue getting this error: SMTP: Invalid response code received from server (code: 530, response: 5.7.0 Authentication Required. For more information, go to 5.7.0. It than provides a URL that is invalid.

      I know pfsense also offers Telegram, Pushover, and Slack as alternatives, but ACME specifically asks for an email address. Including a regular email doesn't work, and I'm unable to receive any emails. I've been trying to set up SSL certificates for my homelab. I know there are alternatives like NGINX, SWAG, and Traefik. I haven't been able to get NGINX to work for whatever reason, unless I'm using self-signed certificates, but the self-signed certificates errors drive me crazy. I don't know enough about SWAG, and don't have the competence to use traefik.

      If anyone can shed any light on this, especially if you have used ACME, I am all ears. If you have additional questions please let me know. Thank you,

      SteveITSS 1 Reply Last reply Reply Quote 0
      • SteveITSS Offline
        SteveITS Rebel Alliance @dhpo5683
        last edited by SteveITS

        @dhpo5683 IIRC Google does [not] allow SMTP anymore? Could be wrong though.

        For the other uncheck the “secure” box and it should still use STARTTLS after making the connection.

        To upgrade, select your branch in System/Update/Update Settings. When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
        Only install packages for your version of pfSense.
        Upvote 👍 helpful posts!

        D 1 Reply Last reply Reply Quote 0
        • stephenw10S Offline
          stephenw10 Netgate Administrator
          last edited by stephenw10

          Works fine for me using Google SMTP. You do have to use the single device login token thing, or whatever Google are calling it these days.

          Edit: *App Password

          SteveITSS 1 Reply Last reply Reply Quote 0
          • SteveITSS Offline
            SteveITS Rebel Alliance @stephenw10
            last edited by

            @stephenw10 my bad then, I lose track. M365 is killing off options one by one.

            To upgrade, select your branch in System/Update/Update Settings. When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
            Only install packages for your version of pfSense.
            Upvote 👍 helpful posts!

            1 Reply Last reply Reply Quote 1
            • D Offline
              dhpo5683 @SteveITS
              last edited by dhpo5683

              @SteveITS I get the same error message even after unchecking it.

              @stephenw10 That's the weird thing, I am using the dedicated login info for both Proton and Gmail. Do I need to open ports to make it seem like a legitimate mail server?

              GertjanG 1 Reply Last reply Reply Quote 0
              • stephenw10S Offline
                stephenw10 Netgate Administrator
                last edited by

                Nope you shouldn't need to open anything. It's an outbound connection that would be allowed by default. Unless you have added outbound block rules?

                D 1 Reply Last reply Reply Quote 0
                • D Offline
                  dhpo5683 @stephenw10
                  last edited by dhpo5683

                  @stephenw10 I haven't. This is a fresh installation. I also think Proton made it so you don't need to use their bridge to use SMTP. I'm honestly at a loss.

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S Offline
                    stephenw10 Netgate Administrator
                    last edited by

                    Run a pcap on WAN for the remote port. Make sure it is at least trying to connect out and sees some sort of reply.

                    1 Reply Last reply Reply Quote 0
                    • GertjanG Offline
                      Gertjan @dhpo5683
                      last edited by Gertjan

                      @dhpo5683 said in How are you supposed to set up Email notifications?:

                      Do I need to open ports to make it seem like a legitimate mail server?

                      Google not working ?

                      b87c2bde-c2ce-44d4-a640-498fc26a46ea-image.png

                      works fine.

                      There is one important hidden thing not shown here :
                      This one :

                      e4d32eca-99d8-4e2f-bd0d-ea3c0495d44f-image.png

                      Repeat after me : this should never ever be your gmail password, the one you use as a person.
                      (pfSense isn't a person, its a "machine" )

                      So, a couple of years ago, app password were invented.
                      In your Google account, create an "app password". You can give it it name like 'MyFsense".
                      Google will give you a password like "fhfgfgf dsdfsdf dfsfsf sdfsfsf". Copy paste this twice here :

                      118eb272-5071-4ccd-91b6-2bd6a64dcd0d-image.png

                      Done.
                      Well .... Nearly.
                      When I access my Google account, I can't find these app passwords anymore.

                      90192da2-a5e0-4f69-872d-179b30083866-image.png

                      Do this :

                      9227f177-40ee-4379-bf38-185ab38cb982-image.png

                      Type "app passwords" and you'll find them :

                      422358d2-c506-4e5e-9d21-2c3154e317b0-image.png

                      That's the place where you can add your pfSense 'machine' password.
                      I've 3 of them, as you can see.

                      This became 'mandatory' years ago ... here in France (that Europe).
                      Maybe elsewhere security is

                      Btw : why all this ? Easy ? Go visit a land fill, and you find old printers computers access points, NAS, doorbells, lightbulbs ... whatever. JTAG them, get the info out and you'll get some one password ^^
                      With this app password system, you visit your app password list and ditch the old ones, the ones you don't need anymore without going over the process of changing your real 'human 'password.

                      Also : pfSense itself is behind the WAN interface, so floating firewall rules aside (by default none) it can go everywhere it wants. So it can go out, find the A or AAAA of gmail (Google) and send a mail.
                      Yo don't use the 25 port, as that port is reserved for other mail servers only. Not mail clients, such as pfSense in this case. pfSense isn't a mail server (our ISPs, in the end of last century really f*ck#d up telling people to use '25' as a mail server).
                      Btw : I use '465' as that still works. Better is probably the good old submission port = 587.

                      No "help me" PM's please. Use the forum, the community will thank you.

                      D 1 Reply Last reply Reply Quote 2
                      • D Offline
                        dhpo5683 @Gertjan
                        last edited by

                        @Gertjan lol. Apparently the issue was I didn't have the "from e-mail address" field filled out correctly. Thank you for this.

                        GertjanG 1 Reply Last reply Reply Quote 0
                        • GertjanG Offline
                          Gertjan @dhpo5683
                          last edited by

                          @dhpo5683
                          Ah, ok, lol.
                          You could even use your own gmail mail here.

                          No "help me" PM's please. Use the forum, the community will thank you.

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
                          Privacy Policy · Cookie Policy