Your mail client says the certificate is not trusted or does not match.
WHY IT HAPPENS
You are connecting to mail.yourdomain.com but the certificate does not cover that hostname. Usually because AutoSSL has not issued for the mail subdomain, or the domain does not yet resolve to us.
THE PROPER FIX
- Confirm the domain resolves to our server.
- cPanel > SSL/TLS Status, tick the domain and its mail subdomain, and run AutoSSL.
- Wait a few minutes, then reconnect.
THE INTERIM FIX
Use the server hostname from your welcome email as the incoming and outgoing server instead of mail.yourdomain.com. That hostname is covered by the server's own certificate, so no warning appears.
WHAT NOT TO DO
Do not tick "do not verify certificate" or accept an invalid certificate permanently. That disables the check that protects your password in transit, and it hides a genuine problem if one appears later.
IF AUTOSSL WILL NOT ISSUE FOR THE MAIL HOSTNAME
Check the mail subdomain exists in DNS, and that Cloudflare is not proxying it. Mail records must be DNS-only.