Yealink phones have an extra layer of security on them by default, only allowing TLS Encryption to be activated by suppliers the phone has been told it can trust.
The exact setting is called "Only accept Trusted Certificates" and can be found under Security > Trusted Certificates when logged into the web interface of a Yealink phone. This needs to be set to "Disabled" for TLS to be enabled. A screenshot of the exact setting can be found below:

By changing this setting your phone will of course still use TLS for your SIP traffic and encrypt it; the setting just defines whether we have to tell it about our certificate first or whether it can just trust we are good guys. Hopefully by now you know we are, so giving you a certificate won't help prove that!
Once you've removed this restriction on TLS, you can now head into the relevant SIP account on your Yealink phone and change:
The transport type to TLS
The SIP server port to 5061
Please find below a screenshot of the SIP TLS Transport setting:

Remember you also need to turn on Call Encryption to use TLS. This is done under Account > Advanced and changing RTP Encryption to “Compulsory”:
If you need any further help today, please don't hesitate to contact our friendly support team on 0330 122 6000 or by email!