Test an SMTP server connection

Enter a mail server and port. We open a connection, read the greeting, check STARTTLS or TLS, optionally try the login, and show you every step with the server's exact reply and timing.

Tries AUTH with these credentials once. Nothing is stored.

We connect, say hello and hang up. Credentials are not stored.

What an SMTP test checks

An SMTP conversation has a fixed shape, and a connection that fails always fails at one line of it. First the hostname has to resolve. Then a TCP connection has to open on the port, which is where firewalls and blocked ports show up. The server then sends a greeting that starts with 220, and the client introduces itself with EHLO, to which the server replies with the list of extensions it supports: STARTTLS, the authentication methods, the maximum message size.

On port 587 the client then says STARTTLS and the same connection is upgraded to an encrypted one; on 465 the connection is encrypted from the first byte. Only after that does a client send its username and password. This tool walks those steps one at a time and reports the server's exact reply at each, which is the part a simple "could not connect" error in your app hides.

Why does my app say connection timed out?

A timeout at the connect step means no packet came back at all. Three things cause it. The port is blocked between you and the server, which is almost always the case for port 25 from a cloud host or a home connection. The hostname is right but the port is wrong, so you are knocking on a door nobody answers. Or the server really is down. A refused connection is different: the host answered and said nothing listens there, which points at the port.

A timeout after the connection opened, during the greeting or EHLO, is usually a server that is deliberately slow with new clients, or a middlebox inspecting the traffic. Try 465 with TLS, where the whole exchange is encrypted from the start and inspection cannot interfere.

How to test SMTP from the command line

If you prefer a terminal, the same conversation can be had by hand. For a STARTTLS server run openssl s_client -starttls smtp -connect smtp.example.com:587, and for an implicit TLS server openssl s_client -connect smtp.example.com:465. Once you see the 220 greeting, type EHLO test and read the reply. The advantage of running it from a machine inside your own network is that it tests your path to the server, not ours.

Sending from your own domain with none of this to set up is what Faivelo's transactional email is for: one SMTP host, one key per app, and the DNS records written for you.

Skip the SMTP debugging entirely.

Faivelo gives every app its own SMTP credentials and API key on your domain, with SPF, DKIM and DMARC written into DNS for you. Password resets and receipts reach the inbox from day one.

Send from my domain

Free tier for transactional mail. No card needed.

Questions people ask