SMTP ports 465, 587 and 25: SSL, STARTTLS and which one to use

To send e-mail from Outlook, your phone or a program of your own, use port 465 with SSL/TLS, which is the one our guides give. Port 587 with STARTTLS is the alternative some applications ask for. Port 25 is not for you. All three exist on the server; what changes is who they were made for and how well protected the connection is.

The three ports, side by side

Port What it is for Encryption When to use it
465 Sending from your own programs (submission), with the connection encrypted from the start. SSL/TLS from the first byte. The first choice. It is the one our POP and IMAP article gives.
587 Sending from your own programs (submission), starting unencrypted and asking for encryption next. STARTTLS: the connection opens and then upgrades to encrypted. When the program asks for “STARTTLS” or 465 does not work on your network.
25 Delivering mail between servers. Optional, at the servers’ discretion. Never in your own programs. Many networks block it outbound.

SSL and STARTTLS: what is the difference

Both protect the password and the message. With SSL/TLS (465) the connection is born encrypted. With STARTTLS (587) it is born in the clear and the program asks the server to switch to encrypted before sending the password. If the program is badly set up and does not insist on that step, the password can travel unprotected. That is why 465 is harder to get wrong, and it is our recommendation.

The values in your e-mail program

1 Outgoing server: mail.yourdomain.tld (replace with your domain). Use this name and not the IP address: a certificate is issued for names, not for numbers.
2 Port and security: 465 with SSL/TLS, or 587 with STARTTLS.
3 Authentication: on, with the full e-mail address as the user name and the mailbox password.
4 Test by sending a message to yourself and to another address. If it does not arrive, see why your e-mail is not sending or receiving.

Checking that the port answers (optional)

On a computer with a command line, these two tests show whether the port opens and whether the server presents its certificate. Replace the name with your own domain:

openssl s_client -connect mail.yourdomain.tld:465
openssl s_client -starttls smtp -connect mail.yourdomain.tld:587

If the connection waits until it gives up, the port is blocked on your network, not on the server. This happens on company networks, in hotels and with some operators. Try the other port, or another network such as your phone’s mobile data. See which ports are open, and why your integration hangs.

“No encryption” is not an option. Some old applications offer 25 or 587 with no encryption at all. Sending like that puts the mailbox password in view of anyone on the same network. If the application supports neither SSL/TLS nor STARTTLS, change application.
Certificate errors are almost always the server name. If the program warns that the certificate does not match, check that you typed mail.yourdomain.tld and not the IP address or another name. See the most common Outlook errors.

The port will not open or the program rejects the password? Tell us which program you use and the message it shows.

Open a support ticket

SEE ALSO

POP or IMAP: which to choose, and what you lose by picking wrong

Why your e-mail is not sending or receiving

Common Outlook errors: 0x800CCC0E, password prompts and more

Professional e-mail

RECOMMENDED PRODUCT

Web hosting with cPanel

Domain and SSL included, daily backups and the panel you already know. from $6.60/mo (3-year plan, with coupon)

See plans
  • 0 Users Found This Useful
Was this answer helpful?