Sending email: port 25
Outbound port 25 is blocked by default on new servers. Why, how to test it, and how to ask for it to be opened for a real mail server.
New VPSNine servers can't make outbound connections to port 25, the port mail servers use to hand mail to each other. The block is outbound only, so mail coming in on port 25 isn't affected.
Why we block it
Spam gets whole ranges of IP addresses blocklisted, fast. One compromised server pumping out spam can stop mail from every other customer near it getting delivered. Blocking port 25 by default protects the reputation of addresses you (and everyone else here) depend on. The Acceptable Use Policy has the rules.
You probably don't need it
Most apps never touch port 25. If yours sends password resets or notifications, send them through a transactional email service on its submission port, 587 or 465. Those aren't blocked.
You can test with nc. Debian 12 doesn't include it, so install it there first with apt install netcat-openbsd:
nc -vz -w 5 smtp.example.com 587And to see whether port 25 is open (use a mail server you know accepts connections):
nc -vz -w 5 mail.example.com 25succeeded or open means it's open. A timeout means it's still blocked.
Asking us to open it
If you're running a real mail server, open a support ticket and choose the server. We review it and open port 25 for that server only. Your other servers stay blocked until you ask for them too.
Get these in place first. Receiving mail servers check all of them anyway, and having them ready makes the review quick:
- Reverse DNS for the server's address, pointing at your mail hostname, with a forward record that matches.
- An SPF record for the domain you send from.
- DKIM signing in your mail server.
- A DMARC record.
- A sentence about what the server sends: your own mailboxes, a list people signed up for, and so on.
SPF and DMARC for example.com might look like this:
example.com. TXT "v=spf1 a:mail.example.com -all"
_dmarc.example.com. TXT "v=DMARC1; p=quarantine; rua=mailto:[email protected]"Once it's open
Run the nc test again; it should connect now. Keep an eye on your mail log for the first few days (journalctl -u postfix if you use Postfix) and look for bounces that mention blocklists or reverse DNS.
Spam and unsolicited bulk mail aren't allowed. If we get an abuse report or see a breach, we may warn you or suspend the server, and accounts suspended for abuse aren't covered by the money-back guarantee.