# Sending email: port 25

> Outbound port 25 is blocked by default on new servers. Why, how to test it, and how to ask for it to be opened for a real mail server.

Source: https://vpsnine.com/help/open-port-25 · Updated: 2026-10-10

New VPSNine servers can't make outbound connections to port 25, the port mail servers use to hand mail to each other. The block is outbound only, so mail coming *in* on port 25 isn't affected.

## Why we block it

Spam gets whole ranges of IP addresses blocklisted, fast. One compromised server pumping out spam can stop mail from every other customer near it getting delivered. Blocking port 25 by default protects the reputation of addresses you (and everyone else here) depend on. The [Acceptable Use Policy](https://vpsnine.com/aup) has the rules.

## You probably don't need it

Most apps never touch port 25. If yours sends password resets or notifications, send them through a transactional email service on its submission port, `587` or `465`. Those aren't blocked.

You can test with `nc`. Debian 12 doesn't include it, so install it there first with `apt install netcat-openbsd`:

```bash
nc -vz -w 5 smtp.example.com 587
```

And to see whether port 25 is open (use a mail server you know accepts connections):

```bash
nc -vz -w 5 mail.example.com 25
```

`succeeded` or `open` means it's open. A timeout means it's still blocked.

## Asking us to open it

If you're running a real mail server, [open a support ticket](https://my.vpsnine.com/support/new?category=network) and choose the server. We review it and open port 25 for that server only. Your other servers stay blocked until you ask for them too.

Get these in place first. Receiving mail servers check all of them anyway, and having them ready makes the review quick:

- [Reverse DNS](https://vpsnine.com/help/reverse-dns) for the server's address, pointing at your mail hostname, with a forward record that matches.
- An SPF record for the domain you send from.
- DKIM signing in your mail server.
- A DMARC record.
- A sentence about what the server sends: your own mailboxes, a list people signed up for, and so on.

SPF and DMARC for `example.com` might look like this:

```text
example.com.         TXT  "v=spf1 a:mail.example.com -all"
_dmarc.example.com.  TXT  "v=DMARC1; p=quarantine; rua=mailto:postmaster@example.com"
```

## Once it's open

Run the `nc` test again; it should connect now. Keep an eye on your mail log for the first few days (`journalctl -u postfix` if you use Postfix) and look for bounces that mention blocklists or reverse DNS.

Spam and unsolicited bulk mail aren't allowed. If we get an abuse report or see a breach, we may warn you or suspend the server, and accounts suspended for abuse aren't covered by the [money-back guarantee](https://vpsnine.com/help/money-back-guarantee).
