> But if that was the case I shouldn't see the client cert information > in the Received header either right? Yes, definitely. > It looks like postfix has that information, adds it to the Received > header but does not expose it to milter. Another possibility would be that the client doesn't issue second EHLO after successful STARTTLS. Have you checked that? Regards, Sergey