Home/Blog/Manually Test STARTTLS (SMTP, IMAP, PostgreSQL) in a GUI with Replay
STARTTLSReplaySMTPIMAPPostgreSQLTesting

Manually Test STARTTLS (SMTP, IMAP, PostgreSQL) in a GUI with Replay

Step by step: connect over TCP, exchange the plain-text commands, click Upgrade TLS and continue the session in InterceptSuite Replay. Covers SMTP, IMAP and PostgreSQL.

I

InterceptSuite Team

October 6, 2026·5 min read

Some protocols start in plain text and switch to TLS partway through the same connection. Testing that handshake by hand normally means openssl s_client -starttls or a script. In InterceptSuite, Replay does it in a window: connect with TCP, send the plain-text commands the protocol needs, click Upgrade TLS, and keep going on the same connection.

Last updated 6 October 2026.

The command-line way: openssl s_client

OpenSSL can do the STARTTLS step for several protocols:

openssl s_client -starttls smtp -connect mail.example.com:587 -crlf
openssl s_client -starttls imap -connect mail.example.com:143
openssl s_client -starttls postgres -connect db.example.com:5432

This is the right tool for a quick certificate and cipher check. Which protocols -starttls supports depends on your OpenSSL version, so run openssl s_client -help to see the list. Its limits show up when you want to:

  • type the plain-text commands yourself and watch the replies before the upgrade,
  • test a custom protocol that has its own upgrade message,
  • keep and compare several attempts, or edit bytes in hex.

That is where Replay helps.

The workflow

  1. Open the Replay tab and click + New Session.
  2. Enter the Host and Port, and choose TCP as the protocol.
  3. Send the protocol's plain-text commands (examples below).
  4. When the server agrees to start TLS, click Upgrade TLS.
  5. Send further packets. They are shown as TLS from now on.

Each step is a separate packet in the conversation panel, so you can see exactly what the server replied before and after the upgrade.

InterceptSuite Replay tab with a session open: host, port, protocol, ALPN and Send controls on the left, the conversation of sent and received packets on the right

SMTP

Port 587 (or 25) with TCP. Send:

EHLO test.local
STARTTLS

Wait for 220 Ready to start TLS, click Upgrade TLS, then send EHLO test.local again. The extensions the server offers after the upgrade often differ from the first list, which is worth checking.

IMAP

Port 143 with TCP. Send:

a001 STARTTLS

After a001 OK Begin TLS negotiation now, click Upgrade TLS, then try a002 CAPABILITY and compare it with the plain-text capability list.

PostgreSQL

PostgreSQL asks for TLS with an SSLRequest message instead of a text command. In the Hex tab send these 8 bytes:

00 00 00 08 04 d2 16 2f

The server answers with a single byte: S means it will use TLS, N means it will not. On S, click Upgrade TLS and continue with the startup message.

What to look for

  • A server that still accepts credentials before the upgrade.
  • Commands accepted in plain text that should require TLS.
  • Differences between the plain and post-upgrade capability lists.
  • Servers that continue in plain text if the upgrade is skipped.

Capture first, then replay

If you do not know the client's exact bytes, capture them through InterceptSuite, right-click the packet in Proxy History and choose Send to Replay. Host, port, protocol and payload are copied into a new session. Pair this with Packet Sender alternatives if you are comparing tools.

Start the 7-day trial and try it.

Ready to intercept non-HTTP traffic?

InterceptSuite is the only native GUI MITM proxy for TCP, TLS, DTLS & UDP - used by penetration testers and protocol engineers worldwide.