At 11:45 -0400 Peter Radcliffe wrote:
>Personally I'd never use login passwords for SMTP AUTH - they get used
>in the clear too often (although it's not as bad if you enforce AUTH
>only over TLS/SSL, which I do).
..but it's too late by then! You say (in the clear)
AUTH PLAIN MiMeHaSh..
..and the server replies
503 STARTTLS required before AUTH
Oops. Not a lot you can do about that, except only use MUAs (and MTAs..)
you trust!