"Thunderbird is being managed by your organization." how to get rid of this? my mail is effectively blocked :(
"Thunderbird is being managed by your organization." how to get rid of this? my mail is effectively blocked :( says: DisableAppUpdate: active
Policy Name 3rdparty Set policies that WebExtensions can access via chrome.storage.managed.
I won't be able to see your reply... please use b[redacted email from community support forum]
Geändert am
Alle Antworten (15)
Your company or school is forcing that. There's no way you can get around it. But that policy has nothing to do with blocking messages, so there must be some other problem(s).
Oh this is Linux so updates are controlled by the distribution (your organization) not by the Thunderbird / Mozilla update manager. That is de jure for Linux.
I have to wonder what this has to do with your feeling you have malicious certificates. my guess is they have a very similar root.
Yes some Linux distros like Mint does this confusing message for packaged builds instead of simply saying updates are not done internally but by package updates. Only the official tarball builds of Thunderbird for Linux from say https://www.thunderbird.net/thunderbird/all/ gets internal updates.
Hello there
Thank you to the moderators for clarifying that the Managed by your organization notification is just standard Linux behaviour and not the cause of the email block.
Following up on their helpful insights, I would like to kindly offer a few friendly suggestions to help you troubleshoot and resolve the actual connection issue you are experiencing.
Please try these quick steps to see if they fix the blockage:
Server Settings (in Thunderbird): Go to Account Settings and verify if your incoming (IMAP/POP) and outgoing (SMTP) server details are still correct.
Certificates (in Thunderbird): Navigate to Settings > Privacy & Security > View Certificates and check for any outdated security exceptions blocking your connection.
Firewall (in Linux Terminal): Test if your local firewall is causing the blockage by temporarily disabling it in the Linux terminal using the command: sudo ufw disable.
tried suggestions problem persists: " The certificate for pop.centurylink.net:995 is not valid for that server. Someone could be trying to impersonate the server and you should not continue."
so is the mail certificate from centurylink fake? has my Mail been compromised? along with all my paSSWORDS?
and there are no certificates listed but many 'authorities' why doesn't the mail certificate appear?
Certi�cate mail.centurylink.net Subject Name Country US State/ProvinceLouisiana LocalityMonroe Organization Common Name Lumen Technologies, Inc. mail.centurylink.net Issuer Name Country Organization Common Name US DigiCert Inc DigiCert Global G2 TLS RSA SHA256 2020 CA1 Validity Not BeforeWed, 27 Aug 2025 00:00:00 GMT Not AfterSun, 27 Sep 2026 23:59:59 GMT Subject Alt Names DNS Namemail.centurylink.net DNS Namepop.centurylink.net DNS Namesmtp.centurylink.net DNS Namemx.centurylink.net DNS Namesmtp.embarqmail.com DNS Namepop.embarqmail.com DNS Namem.mail.centurylink.net DNS Namewebmail.centurylink.net DNS Namemail.embarqmail.com DNS Nameimap.embarqmail.com 9/27/26, 18:55Public Key Info AlgorithmRSA Key Size2048 Exponent65537 ModulusB3:14:2C:13:B3:F7:D9:B8:FF:A0:B3:54:D5:D5:B9:B9:B5:8A:D6:70:9… Miscellaneous Serial Number Signature Algorithm Version Download 04:F0:6F:FB:A9:96:5D:57:CD:FC:F6:76:CF:77:C8:3A SHA-256 with RSA Encryption 3 PEM (cert) PEM (chain) Fingerprints SHA-256 SHA-1 11:4A:E9:93:47:1C:89:0C:26:08:C5:05:89:9A:CE:FC:43:E8:AA:AB:4B… 76:C9:FF:F1:F0:02:8E:ED:53:81:F5:7C:33:7F:93:66:9E:6A:FA:8E Basic Constraints Certi�cate Authority No Key Usages Purposes Digital Signature, Key Encipherment Extended Key Usages Purposes Server Authentication, Client Authentication Subject Key ID Key ID 8E:AF:AD:85:35:99:A9:E1:3C:C7:43:29:E7:75:35:8E:6E:D5:EA:AA Authority Key ID 9/27/26, 18:55Key ID 74:85:80:C0:66:C7:DF:37:DE:CF:BD:29:37:AA:03:1D:BE:ED:CD:17 CRL Endpoints Distribution Pointhttp://crl3.digicert.com/ DigiCertGlobalG2TLSRSASHA2562020CA1-1.crl Distribution Pointhttp://crl4.digicert.com/ DigiCertGlobalG2TLSRSASHA2562020CA1-1.crl Authority Info (AIA) Locationhttp://ocsp.digicert.com MethodOnline Certi�cate Status Protocol (OCSP) Locationhttp://cacerts.digicert.com/ DigiCertGlobalG2TLSRSASHA2562020CA1-1.crt MethodCA Issuers Certi�cate Policies PolicyCerti�cate Type ( 2.23.140.1.2.2 ) ValueOrganization Validation Quali�er Value Practices Statement ( 1.3.6.1.5.5.7.2.1 ) http://www.digicert.com/CPS Embedded SCTs Log Name Log ID Signature Algorithm Version Google 'Argon2026h2' log D7:6D:7D:10:D1:A7:F5:77:C2:C7:E9:5F:D7:00:BF:F9:82:C9:33:5A:65… SHA-256 ECDSA 1 TimestampWed, 27 Aug 2025 14:32:04 GMT Log NameDigiCert 'Wyvern2026h2' Log ID Signature Algorithm Version C2:31:7E:57:45:19:A3:45:EE:7F:38:DE:B2:90:41:EB:C7:C2:21:5A:22:… SHA-256 ECDSA 1 TimestampWed, 27 Aug 2025 14:32:04 GMT Log NameDigiCert 'Sphinx2026h2' Log ID 94:4E:43:87:FA:EC:C1:EF:81:F3:19:24:26:A8:18:65:01:C7:D3:5F:38:… 9/27/26, 18:55Signature Algorithm Version Timestamp SHA-256 ECDSA 1 Wed, 27 Aug 2025 14:32:04 GMT 9/27/26, 18:55
Hello there
Your data is 100% safe and has not been compromised.
No worries, we have fully investigated the issue and found the exact answer. The missing piece is CenturyLink’s server certificate, which expired yesterday without your knowledge. The fault lies entirely with CenturyLink.
That is also the reason why it was not pushed to your system and why it wasn't visible under your "Authorities" tab.
You do not need to change or restore any settings in Linux or Thunderbird 😁
Here is what you can do right now as a temporary workaround: try accessing your CenturyLink webmail safely through your internet browser at www.centurylink.net.
For the permanent fix: just wait. Once CenturyLink updates their servers with a new certificate, Thunderbird will automatically start working again on your internet connection.
Cause If you look at the validity dates in your log for CenturyLink/Lumen Technologies, the exact cause is right there:Not Before: Wed, 27 Aug 2025Not After: Sun, 27 Sep 2026 23:59:59 GMT
The mail server's certificate expired yesterday.
Geändert am
Hello there
You can speed up the process by closing and restarting Thunderbird. A pop-up window titled 'Confirm Security Exception' should appear right away.
Check the box for 'Permanently store this exception' and click the Confirm Security Exception button.
Your emails should start coming through immediately after.
Please let us know if this takes care of the issue. If you don't see the pop-up, you can always try adding the exception manually.
Geändert am
thanks; I thought of that but it seemed unlikely that CenturyLink would terrorize hundreds of thousands of customers; I hope you're correct and I appreciate your assistance; still no email this morning; I've been up most of the night fretting over this: I guessed the expired mail certificate was a malicious forgery to block my email and gain access to my account; yes, I saw that webmail was still seeing incoming messages, which was somewhat assuring... /:b
still blocked; even after accepting exception (I've done this a dozen times already); how to set exception manually please?
I've gone through all the Authorities and none match the Certificate. And now I see that the validity date has been changed!
"Issuer Name Country US Organization DigiCert Inc Common Name DigiCert Global G2 TLS RSA SHA256 2020 CA1 Validity Not Before Thu, 09 Oct 2025 00:00:00 GMT Not After Tue, 13 Oct 2026 23:59:59 GMT
Hello there
there was some initial doubt about whether security certificates were the root cause, your troubleshooting information provides a clear explanation of what is happening.
The certificate for the server address expired yesterday (September 27, 2026). CenturyLink has officially let the SSL/TLS certificates for the legacy centurylink.net and embarqmail.com servers expire without renewing them.
This is part of their active 2026 migration to transition users over to the new @myctl.net platform.Because Thunderbird is designed to protect your security, it is blocking the connection because it detects this expired certificate. Your internal system configuration didn't change, but your provider has updated their security requirements on their end.
To resolve these verification errors on your screen, we need to update your client application from the pre-migration setup to the active servers.
Could you please review your current settings and let us know:Whether your account is configured as a POP or IMAP account.What exactly your current incoming and outgoing (SMTP) server settings and port numbers are.Which version of Thunderbird you are currently running.
If needed, you can share screenshots of your configuration settings by following this official guide:mozilla.orgLet us know what you find so we can guide you through the exact update steps to get your email working again!
Use
https://support.mozilla.org/en-US/kb/how-to-make-screenshots
Geändert am
Hello there
The shift to October 13, 2026 actually confirms our analysis. The provider likely issued a temporary extension because many legacy users lost connection when the previous certificate expired.
The reason you still see errors and no Authorities match is that Thunderbird is still pointing to the old server paths.
The updated certificate configuration requires the new server infrastructure to work properly. To resolve this, we still need to verify whether your account is set up as POP or IMAP, along with your current server and port settings as requested above.
Once we update these to the 2026 requirements, the errors will disappear.
Geändert am
manythanks for all the help and assurance: email was finally restored (with thousands of old messages) but up and running again :)