Short answer: Use port 587 with STARTTLS or port 465 with implicit TLS when a website, app or mail client sends mail through your mail provider; both require a username and password. Port 25 is for mail servers delivering to other mail servers, and many hosting and cloud providers block it for outgoing connections. The port only decides how you connect to the sending server; whether mail reaches the inbox depends on SPF, DKIM, DMARC and your reputation.
What an SMTP port is
SMTP (Simple Mail Transfer Protocol) is the protocol used to send e-mail. When a program sends a message, it opens a network connection to a mail server on a specific port number. Different ports exist because sending mail involves two different jobs:
- Relay: one mail server passing a message to another mail server, for example from your provider’s server to the recipient’s server at Gmail or Outlook.
- Submission: a user or application handing a new message to its own mail server, after logging in, so that server can relay it onwards.
Mixing these two jobs up is the source of most port problems. A website contact form, a shop sending order confirmations or a phone mail app is doing submission. Only the mail servers themselves should be doing relay.
Port 25: server-to-server relay
Port 25 is the original SMTP port and is still the standard port for delivery between mail servers. When your provider delivers your message to the recipient’s domain, it looks up the recipient’s MX records and connects to that server on port 25.
For applications, port 25 is usually the wrong choice:
- Many internet service providers and cloud platforms block outgoing connections on port 25 by default, because infected computers and servers have long used it to send spam directly.
- Mail sent directly from a web server to recipients on port 25 comes from an IP address with no mail reputation and often no matching reverse DNS, so it is frequently rejected or filtered.
- Encryption on port 25 is opportunistic: servers use STARTTLS when both sides support it, but the connection may still fall back to plain text unless a policy such as MTA-STS requires encryption.
If your website “sends mail” with the default PHP mail function and no SMTP settings, it is often doing exactly this. Our guide to WordPress emails going to spam explains why that setup is unreliable and how to switch to authenticated sending.
Port 587: submission with STARTTLS
Port 587 is the standard port for message submission. The client connects in plain text, issues the STARTTLS command to upgrade the connection to TLS, then logs in with a username and password and sends the message.
- It is supported by practically every mail provider and transactional e-mail service.
- It is rarely blocked by hosting providers, because it requires authentication.
- The client must be set to require STARTTLS. If it is set to “use TLS if available”, a network attacker could strip the upgrade offer and the login would happen unencrypted.
In mail client and plugin settings, this combination is often labelled “TLS” or “STARTTLS” with port 587.
Port 465: submission with implicit TLS
Port 465 has a confusing history. It was assigned for SMTP over SSL in the 1990s, then its registration was withdrawn and many guides called it deprecated. In 2018, RFC 8314 registered it again for message submission over implicit TLS and recommended implicit TLS over STARTTLS for mail clients.
With implicit TLS, the encrypted connection starts immediately; there is no plain-text phase that could be tampered with. In settings screens it is usually labelled “SSL” or “SSL/TLS” with port 465.
In practice, both 465 and 587 are secure when configured correctly. Use whichever your provider documents, and make sure the encryption setting matches the port.
The table below summarises the ports side by side.
| Port | Purpose | Encryption | Authentication | Use it for |
|---|---|---|---|---|
| 25 | Relay between mail servers | Opportunistic STARTTLS | Not for relay | Mail servers only |
| 587 | Submission | STARTTLS (should be required) | Required | Websites, apps, mail clients |
| 465 | Submission | Implicit TLS from the start | Required | Websites, apps, mail clients |
| 2525 | Unofficial alternative submission port | Depends on provider | Required | Only when a provider offers it and other ports are blocked |
Port 2525 is not a standard. Some transactional e-mail services offer it as a fallback for networks that block the usual ports; use it only if your provider documents it.
Which port to use for common setups
- WordPress or other CMS: install an SMTP plugin or use your platform’s mail settings, connect to your mail provider or transactional service on 587 (STARTTLS) or 465 (SSL/TLS), and log in with a dedicated account or API key.
- Online shop: the same, ideally with a transactional e-mail service that signs mail with DKIM for your domain. If customers do not receive receipts, see order confirmation emails not arriving.
- Printers, scanners and office devices: use 587 or 465 with authentication if the device supports modern TLS. Old devices that only support outdated encryption may need a local relay or a provider’s dedicated connector.
- Mail apps on phones and laptops: the provider’s automatic setup normally chooses correctly. For manual setup, use the port and encryption the provider lists.
- Your own mail server: it receives mail on 25, accepts submissions from users on 587 and/or 465, and sends to other servers on 25.
Troubleshooting common SMTP errors
Most sending failures from websites and devices fall into a few patterns:
- Connection timed out. The port is blocked, usually by the hosting provider’s firewall. Try 587 or 465 instead of 25, or ask the host whether outbound SMTP is allowed.
- “Wrong version number” or SSL handshake errors. The encryption setting does not match the port: SSL/TLS configured on 587, or STARTTLS configured on 465. Swap the setting.
- Authentication failed. Wrong username or password, or the provider requires an app password or API key instead of the normal login. Some providers also disable basic SMTP login by default.
- “Relay access denied”. The client is not logged in, or it is sending on port 25 to a server that does not accept relay. Enable authentication and use a submission port.
- Certificate errors. The host name in the settings does not match the server’s certificate, for example using an IP address instead of the provider’s SMTP host name.
To test a connection from a server, you can use OpenSSL: openssl s_client -connect smtp.example.com:465 for implicit TLS, or openssl s_client -starttls smtp -connect smtp.example.com:587 for STARTTLS. A certificate and a “220” greeting mean the port is open and encryption works.
Keep SMTP credentials safe
An SMTP login stored in a website is a valuable target. If attackers get it, they can send spam or phishing through your provider with your domain, which damages your reputation and can get the account suspended. A few habits reduce that risk:
- Use a dedicated account or API key for each website or device, not the owner’s personal mailbox password.
- Prefer API keys with limited permissions where the provider offers them, for example “send only” without access to the mailbox or account settings.
- Store secrets outside the web root or in the platform’s protected configuration, not in theme files or plugin settings that may be exported or backed up publicly.
- Rotate credentials when a developer or agency stops working on the site, and after any security incident.
- Watch sending volumes. A sudden spike in outgoing mail, bounces or complaints is often the first sign that credentials have leaked.
The port does not decide deliverability
Choosing 587 instead of 25 fixes connection problems, not spam-folder problems. Once the message is accepted, the receiving server judges it on authentication and reputation:
- Your SPF record must include the service that sends the mail.
- That service should sign with DKIM using your domain.
- Your DMARC record tells receivers what to do when checks fail.
- Content, complaint rates and sending history do the rest.
If you add a new sending service, follow the steps in how to authenticate third-party email senders. For how encryption between servers works after submission, see TLS and STARTTLS explained.
What Site AI Audit checks for e-mail
Site AI Audit checks the DNS side of your e-mail setup: whether your domain has MX records, a valid SPF record within its lookup limit, DKIM signatures and a DMARC policy. These records decide whether mail sent through the right port is also trusted by the receiving side. Each finding explains what is missing and how to fix it. You can run a free check to see where your domain stands.
Related reading
- MTA-STS and TLS-RPT: Enforcing Encrypted Email Delivery
- SPF Record Explained: What It Does and How to Set It Up
- Reverse DNS and PTR Records for Email: What You Need to Know
The bottom line
Websites, apps and mail clients should submit mail on port 587 with STARTTLS or port 465 with implicit TLS, always with authentication. Port 25 is for mail servers talking to each other. Match the encryption setting to the port, and remember that inbox placement depends on SPF, DKIM, DMARC and reputation, not the port number.
DUK
Should I use port 587 or 465?
Both are secure for sending with authentication. Port 465 uses TLS from the first byte, while 587 upgrades with STARTTLS. Use whichever your mail provider documents, and match the encryption setting to the port.
Why is port 25 blocked on my server?
Many hosting, cloud and internet providers block outgoing port 25 to stop compromised machines from sending spam directly. Use an authenticated submission port with your mail provider instead.
Is port 465 deprecated?
No longer. It was withdrawn for a time, but RFC 8314 registered it again in 2018 for message submission over implicit TLS, and it is widely supported.
Does changing the SMTP port fix emails going to spam?
Usually not. The port affects whether you can connect and send. Spam placement depends on SPF, DKIM, DMARC, reputation and content.
What does “wrong version number” mean in SMTP settings?
It usually means the encryption method does not match the port, such as SSL/TLS selected for port 587. Use STARTTLS on 587 and SSL/TLS on 465.



