>> My previous assesment was wrong: even when exim was compiled with
>> OpenSSL instead of GnuTLS the error did occur, albeit with a different
>> error message.
> Same here.  The new error message is:
> SSL_write: (from host.outbound.protection.outlook.com
> (host.outbound.protection.outlook.com) []:1234) syscall:
> connection reset by peer
> My server runs in a KVM.  Doesn't that rule out hardware TCP offloading
> as the culprit?

No, it rather makes the problem more likely.  Virtual machines are often
behind NAT, which can be incompatible with TCP offload, and there are likely
other issues.  If you search the web for "KVM TCP offload" you'll see many
problem reports and advice to turn it off.


