This SMTP test connects to your mail server the way an email client does, reads the greeting banner, negotiates encryption and reports what it finds. It is the quickest way to confirm that a new certificate is live on the mail service, that STARTTLS works after an Exim or Postfix change, and that the server offers the authentication methods your users need. No message is sent: the test stops after the handshake and says QUIT.
Short answer: Enter the mail server hostname and choose port 587 (STARTTLS) or 465 (implicit TLS). A healthy result shows a 220 banner, STARTTLS negotiated with TLS 1.2 or 1.3, a certificate whose name matches the hostname with more than 14 days left, AUTH methods such as LOGIN and PLAIN offered only after TLS, and a reverse DNS name that resolves back to the server IP.
Table of Contents
Reading the result
- Banner: the 220 greeting. A slow banner (several seconds) often means the server is doing reverse DNS lookups that time out.
- Encryption: port 587 must offer STARTTLS; port 465 is TLS from the first byte.
- TLS certificate: must cover the hostname clients use. cPanel and DirectAdmin install the hostname certificate for Exim and Dovecot automatically when AutoSSL covers the server hostname.
- SMTP AUTH: the login methods offered after encryption. None on a submission port means users cannot authenticate.
- Reverse DNS: the PTR record of the server IP and whether it resolves back. Receivers use it as a basic trust signal.
The full SMTP conversation is shown line by line, so you can compare it with what your MTA logs.
Why port 25 is not offered
Outbound connections on port 25 are blocked from our server, as they are on most cloud and hosting networks, to stop spam. To test server-to-server delivery on port 25, run this from any server that is allowed to connect out on port 25:
openssl s_client -starttls smtp -connect mx.example.com:25 -servername mx.example.com
swaks --to postmaster@example.com --server mx.example.com --tls --quit-after RCPT
Common fixes
A mismatched or self-signed certificate is the most frequent finding: issue a certificate for the mail hostname and restart the MTA. If STARTTLS is missing, check the tls_certificate settings in Exim or smtpd_tls_cert_file in Postfix. For reverse DNS, only the owner of the IP range (your host or ISP) can set the PTR record.
SMTP test at a glance



How to use this tool
- Enter the hostname your mail clients use for outgoing mail, for example
mail.example.comorsmtp.example.com. You can paste it withsmtp://or a port; only the hostname is used. - Choose the port: 587 (submission with STARTTLS) or 465 (submission with implicit TLS). Test both if your users have a mix of mail clients.
- Press Test SMTP. The test opens a connection (10-second timeout), reads the greeting, sends
EHLO, upgrades to TLS, sendsEHLOagain and ends withQUIT. - Read the summary, then the conversation table to see exactly what your server answered.
Enter a mail hostname, not just your domain. On ports 587 and 465 the test connects to the A record of whatever you type. For a bare domain that is usually the website, which may be on a different server or behind a CDN that does not pass mail traffic. Results are cached for 5 minutes, so wait a few minutes before re-testing after a change.
How to read the results
| Row | Good result | What else you may see |
|---|---|---|
| Banner | 220 followed by the server name, for example 220 mail.example.com ESMTP. | 421: the server is refusing new connections for now (connection limit, overload or a block on our IP). 554: the server rejects the connection outright. Nothing: the port is open but the service did not answer. |
| Time to banner | Under a second. | Amber above 5 seconds. Mail clients may time out, and receivers treat slow servers with suspicion. |
| Reverse DNS | A PTR name that resolves back to the server IP (forward-confirmed). | does NOT resolve back or no PTR record. Matters mainly for servers that also send mail to other servers. |
| Encryption | STARTTLS offered and negotiated on 587, implicit TLS (SMTPS) on 465. | no STARTTLS: passwords and mail would travel unencrypted. |
| TLS certificate | The name matches the hostname you entered, it is not self-signed and has more than 14 days left. | Amber if the name does not match, the certificate is self-signed, or it expires within 14 days. This row checks name, dates and self-signing; for a full chain-of-trust check use the SSL certificate checker with :465. |
| TLS version / cipher | TLSv1.3 or TLSv1.2. | Anything older is marked amber; TLS 1.0 and 1.1 are deprecated (RFC 8996). |
| SMTP AUTH | The login methods, for example AUTH PLAIN LOGIN, read after TLS. | not offered on a submission port means mail clients cannot log in. |
| Extensions | The EHLO keywords the server supports. | Common ones: SIZE (largest message accepted, in bytes), PIPELINING, 8BITMIME, SMTPUTF8, CHUNKING, ENHANCEDSTATUSCODES, DSN. |
In the conversation table, C lines are what our server sent and S lines are your server’s replies. A ! line marks a TLS negotiation that failed. Compare the timestamps in your MTA log with the time shown in the result to find the matching log lines.
Common problems and how to fix them
“Could not connect to mail.example.com (203.0.113.10) on port 587: Connection timed out”
Nothing answered within 10 seconds, so a firewall is dropping the connection or the hostname points to the wrong server. Check that the hostname resolves to the mail server and not to a CDN: on Cloudflare the mail hostname must be DNS only (grey cloud), because the proxy does not carry SMTP. Then check the server firewall:
dig +short mail.example.com
grep -E '^TCP_IN' /etc/csf/csf.conf # CSF: 587 and 465 must be listed
firewall-cmd --list-ports --list-services # firewalld
“Connection refused”
The server is reachable but nothing listens on that port. On cPanel and DirectAdmin, Exim listens on 25, 465 and 587 by default, so a refusal usually means Exim is stopped. On Postfix, port 587 needs the submission service and 465 the submissions service (called smtps in older versions) uncommented in master.cf. See what is listening:
ss -tlnp | grep -E ':(25|465|587)\b'
systemctl status exim # or: systemctl status postfix
Certificate does not cover the hostname, or is self-signed
The MTA is still using the certificate created at install, or a certificate for another name. On cPanel, make sure AutoSSL covers the server hostname, then check WHM » Manage Service SSL Certificates; mail clients can also use mail.example.com once AutoSSL has issued a certificate that includes it. On DirectAdmin, read DirectAdmin old certificate after renewal. On plain Postfix, point smtpd_tls_cert_file and smtpd_tls_key_file at the full-chain certificate and its key, then reload.
“no STARTTLS” or “TLS negotiation failed”
Either the server does not advertise STARTTLS or the handshake broke. The usual causes are a certificate file path that no longer exists after a renewal, a key that does not match the certificate, or a protocol setting that only allows versions our client refuses. Postfix logs this as 454 4.7.0 TLS not available due to local problem; the line before it names the file it could not load.
postconf smtpd_tls_cert_file smtpd_tls_key_file smtpd_tls_security_level
journalctl -u postfix --since '15 min ago' | grep -i tls
On Exim the settings are tls_certificate, tls_privatekey and tls_advertise_hosts; on cPanel change them through WHM rather than editing the file, or your edit is overwritten.
SMTP AUTH not offered
Many servers advertise AUTH only after TLS, which is correct, and the test reads the list after the upgrade. If AUTH is still missing, authentication is switched off on that port. On Postfix, the submission service needs -o smtpd_sasl_auth_enable=yes in master.cf. If TLS failed, fix that first: with smtpd_tls_auth_only = yes Postfix never offers AUTH on an unencrypted session.
Clients log in with “535 Incorrect authentication data”
This is Exim’s reply to a wrong username or password. It is outside what this test does, but it is the next thing people hit. On cPanel and DirectAdmin the username is the full email address. The Exim log shows each failure with the username that was tried:
grep 'authenticator failed' /var/log/exim_mainlog | tail
The banner takes several seconds
The server is waiting on something before it greets, most often a reverse DNS lookup of the connecting IP through a slow or broken resolver. Test the server’s resolver with dig -x 203.0.113.10 run on the server itself; if that takes seconds, fix /etc/resolv.conf or the local resolver.
Official documentation: RFC 8314: TLS for email submission, RFC 3207: SMTP STARTTLS.
Related tools: Domain health checker · MTA-STS checker · Reverse DNS lookup.
Frequently asked questions
Does the SMTP test send an email?
No. It connects, reads the greeting, sends EHLO, negotiates TLS if offered and then QUIT. No MAIL FROM or RCPT TO commands are sent, so nothing is delivered.
Should I use port 587 or 465?
Both are standard for mail clients. Port 465 uses TLS from the start and is preferred by current RFCs; 587 upgrades with STARTTLS. Offering both gives clients the widest compatibility.
Why does my mail server show a self-signed certificate?
The MTA is still using the default certificate created at install time. Issue a trusted certificate for the mail hostname, for example through AutoSSL or Let’s Encrypt, and point the MTA at it.
What is the difference between STARTTLS and implicit TLS?
With STARTTLS (port 587) the connection starts in plain text and the client asks to upgrade before logging in. With implicit TLS (port 465) encryption starts with the first byte. Both are secure when the client insists on encryption.
Is port 2525 a standard SMTP port?
No. Some relay services offer 2525 as an extra submission port for networks that block 587 and 465, but it is not registered for SMTP. Use 587 or 465 where you can.
Can I test my mail server from my own computer?
Yes, with OpenSSL: openssl s_client -starttls smtp -connect mail.example.com:587 -servername mail.example.com, or openssl s_client -connect mail.example.com:465 for implicit TLS. Type EHLO test once connected and QUIT to leave.
Why does my mail client warn about the certificate when this test shows it as valid?
The client may be connecting to a different hostname than the one you tested, for example the bare domain or a server name. The certificate has to cover the exact name in the client’s outgoing server setting.
How do I test sending with a login?
This test stops before logging in, so your password is never needed. To test the full path, use swaks on a machine you control: swaks –to you@example.org –server mail.example.com:587 –tls –auth LOGIN –auth-user you@example.com.
Should port 25 offer AUTH?
Port 25 is for servers delivering mail to each other, which do not log in. Users should submit on 587 or 465; many providers disable AUTH on port 25 to stop password-guessing there.