I suppose it's best indeed. Here is blackblock's conf (the main server)
https://pastebin.com/nAKFADH9
(Please post it on list the next time.)
..
listen on $ip6 inet6 port 10027 filter rspamd
..
That is a clear text connection only. Try
listen on $ip6 port 10027 smtps \
hostname blackblock.22decembre.eu \
pki blackblock
and forgo "filter rpsmad" for now.
I assume you block connections to 10027 from the internet? Because I
tried and can't connect.
Here is Dina's conf (backup)
https://pastebin.com/4ea7QgzU
action "relay" relay \
host smtps://blackblock.22decembre.eu:10027 \
src 2603:c026:306:9211::300
I believe "pki dina" is not necessary here since you are not authenticating.
action "relay" relay host smtp+tls://blackblock.22decembre.eu:10027
pki dina tls
protocols secure src 2603:c026:306:9211:f:10d:c:9f55
Yes
That is not the IP shown in the logs though. So it can't be.
To bad that OpenBSD's "openssl s_client" doesn't have the -bind option
or I would have asked for the output of
openssl s_client -connect blackblock.22decembre.eu:10027 -bind
[2603:c026:306:9211::300]