iPhone cannot verify server identity

Today whenever I enter my e-mail on iOS 10, iPhone 7 a message pops up with 'cannot verify server identity'...previosly this gave you the option to continue, details or cancel...now on iOS 10 the continue option has been dropped so I cannot simply click and get my e-mails...does anyone know how to fix? I have searched online with no joy as all are much older versions of iOS. or based on safari issues.

[Re-Titled by Host]

iPhone 7, iOS 10.0.3

Posted on Oct 19, 2016 1:33 AM

Reply
Question marked as Top-ranking reply

Posted on Feb 21, 2017 12:23 AM

If you're able to receive but not send mail, I can confirm that this is all related to a bug in the SMTP server settings stored on the device. Someone else mentioned a version of this solution earlier, but here's a step-by-step guide to how I finally cleared it up after a day of dangerously high blood pressure:


If you have more than one mail account, skip to step 2.


  1. Only applicable if you have one mail account on your phone: Create a bogus mail account with fake settings. Just get it to be saved as a legit-looking account, and you should be OK.
  2. Delete the problematic account.
  3. In any other mail account, find where all your SMTP servers are listed (Account > SMTP).
  4. The one from the problematic account should still be there. Tap on it to get the details, and hit Delete Server.
  5. Make sure you don't have multiple listings for it. If you do, delete those, too.
  6. Re-add the account you deleted. You should finally get the full Cannot Verify Server Identity dialog with Continue, Details, and Cancel.
  7. Assuming you need to trust the certificate, hit Details. You should see the Trust option. Tap it!
  8. You may need to repeat step 7 to cover both incoming and outgoing servers.
  9. If you created a bogus account in step 1, be sure to delete it or Mail will get stuck on trying to get it to work.


This worked for me. I hope it works for you if you have the same problem I did.

126 replies

Dec 13, 2016 3:01 PM in response to Lurch57

Also experiencing this problem with my iPhone 6s with iOS 10.1.1 and 10.2, connecting to an IMAP server running Postfix and Dovecot and using TLS for both.


Problem began after updating SSL certificate issued by CAcert. Note that CAcert is not listed in the default iOS root certificates, but is installed as a Profile. This combination has always worked before.


I tried deleting the mail account, rebooting the iPhone 6s, and re-setting up the email account. No go with iOS 10.1.1. Updated to iOS 10.2 and repeated email account setup. Incoming server Cannot Verify Server Identity dialog did have the Continue button this time, but outgoing (SMTP) server only gives me Details and Cancel option, no Continue option.


Server log shows that a TLS connection was established, but it then times-out after a while, waiting on the iPhone...


Is there any way to get the outgoing server Cannot Verify Server Identity dialog to give a Continue option?

Dec 28, 2016 6:32 AM in response to GolfProAL

Apple definitely has some things to work out with this issue. Not only do they no longer have the Continue button available (which basically just auto-switched it to non-SSL) but they no longer have a way to accept the certificate when you view the SSL certificate details. This all tends to be related to SMTP, not incoming (but can work for both).


The issue usually comes from misaligned certificates or using the wrong type of security protocol with that certificate.


Potential ways to fix the issue:


1. change the authentication type to password (I think it tries to default to MD5 or something) and make sure you are using the proper username and password


2. use the ISP's actual mail server name (many shared hosting services will tell you your mail domain is "mail.yourdomain.com" but it's not that way on the certificate - it's usually "mail.theISPdomain.com" on the certificate, so it cannot validate.) ... if you do switch to this, you definitely will require your full email address as the username


3. Turn off all SSL until Apple addresses the issue.




@APPLE : you need to either allow the ability to accept the SSL certificate that is available on the server, or to continue and auto-switch to non-SSL as before. You are not going to force ISPs (especially shared hosting environments) to buy a certificate for each domain and it's not feasible for them to order multi-domain certificate when they don't know what domains they will host on a daily basis. You need to follow some modicum of accepted IT networking principals.


@APPLE : While we are on the subject of email ... you also need to stop this anal requirement of inputting incoming and outgoing credentials separately. 99.9% of all mail services are combined and use the same settings for both. You are the only OS and mail client that still requires separate entry, which is really confusing for many people. You should still have an Advanced section where this can be adjusted in the off chance it is required, but for most you should just be setting everything in one swoop during setup. The notion of separate inbound and outbound servers hasn't been used in decades now, except in specialized environments. You also do not require "extra SMTP servers". That was a very old requirement when ISPs used to only let people on their own network use their mail service. That type of validation (again) hasn't been used in decades, especially with the mobile universe we are now living in.

Dec 30, 2016 2:12 PM in response to Lurch57

This didn't work for me. Whether on wifi or cellular, I get the same error when attempting to send. Incoming mail is fine; works like it always did. Luckily I don't have this issue on my MacBook when using Outlook. Cant send with Mail app although it doesn't give the same error; just a generic can't send. This could be something else altogether though.


I used to get the warning and could continue. I think Apple is trying to protect us too much by taking that option away. Everything worked fine before the update as note in the various postings in the thread.

Jan 26, 2017 12:21 PM in response to GolfProAL

This is definitely a problem with iOS 10 and the iPhone 7.


I have the exact same email accounts on both my iPhone and my iPad. Both run the same version of iOS 10.2.1.


When my email certificates were updated by my email service (Dreamhost), I got the same untrusted error on both devices.


Under Details on my iPad, the Trust button appeared and worked fine.


Under Details on my iPhone, the Trust button is missing.


It appears that Apple forgot to include the Trust button on the iPhone.


Please Advise.

Jan 26, 2017 7:16 PM in response to Brian Bard

I had this Same Problem and what I kept doing was Deleting email and then adding back, but that didn't fix

So after a lot of trouble shooting this was what Solved it so I could get the Continue to be able to Trust Certificate

1st Delete the Email Account that's giving you Trouble


2nd Go back to Settings and then Mail then Click on Accounts then click on another email account that you have on there click on it then Outgoing Mail Server

After getting to the Outgoing Mail Server Click on the Email that you deleted in 1st step then Scoll down and

Delete the Server!

3rd and Last Re Add Email Account and the Contiue will pop up to Verify Server


If you need help feel free to message me

Mar 12, 2017 7:09 PM in response to GolfProAL

We started having this issue recently and none of the steps i saw worked. Maybe because the email setup is different. one major factor is that the phone did not give you the option to trust or accept the untrusted certificate. We are connecting via SSL, to our exchange server. Issue i used to resolve it was on the mobile config file i enabled untrusted TLS accepting(this was initially disabled) . i then exported our exchange cert and added to the mobile config. exchange was able to sync after reinstalling and users were able to accept the certificate.


guess a FYI who may still have issues since i had to spend a weekend playing around with the phone and certification issue. phones were using version 10.2.1

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

iPhone cannot verify server identity

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.