What port 25 is actually for
Port 25 is SMTP relay: the port mail servers use to hand messages to each other. When Gmail delivers to your mail server, it connects to your port 25.
It is not the port your mail client or your application should use to send. That is submission, and it belongs on port 587 with authentication — a distinction formalised in 1998 and still widely misunderstood.
The problem it creates
Port 25 predates the idea that the internet might contain bad actors. It requires no authentication by design, because in 1982 every host on the network was operated by someone you could phone.
The consequence today: any machine that can open outbound connections on port 25 can send mail claiming to be from anyone. A compromised server — an out-of-date WordPress, a leaked SSH key, a weak database password — becomes a spam relay in minutes.
And the damage is not confined to that machine. Blacklists like Spamhaus operate on IP ranges. One compromised server in a /24 can get the whole block listed, and then nobody in that range can deliver mail to Gmail, Outlook or anywhere else that consults the list.
So it is blocked, almost everywhere
We block outbound 25 by default. So does AWS, so does Google Cloud, so does Azure, so does DigitalOcean, and so does most Indian broadband and every mobile network. This is not a hosting policy; it is internet-wide practice with thirty years of justification behind it.
Worth reframing: the block is not a restriction on you. It is the reason the IP you were allocated can deliver mail at all.
What to use instead
| You want to | Use |
|---|---|
| Send from a mail client | Port 587, STARTTLS, authenticated |
| Send from an application | Port 587 to your mail host or an SMTP provider |
| Send bulk or transactional mail | A transactional provider, over 587 or their API |
| Receive mail | Inbound 25 — open, and always was |
| Run your own mail server | Talk to us; outbound 25 can be opened |
For a WordPress site this is a five-minute change: install an SMTP plugin, point it at port 587 with a mailbox and password, and stop using PHP's mail(). Mail sent through mail() from a web server has poor deliverability even where port 25 is open, because it arrives without authentication from an IP with no mail reputation.
The full port reference is in our email port numbers guide.
Opening it
On a VPS or dedicated server, outbound 25 can be opened. We ask four things first:
- What mail server software, and is it configured to refuse open relay?
- What volume, and to whom — transactional, or a list?
- Are SPF, DKIM, DMARC and reverse DNS in place? Without them the mail will not be delivered anyway.
- Who is on the other end of an abuse report at 3am?
These are not obstacles. They are the same questions any competent mail operator asks themselves, and if the answers are ready the block comes off. Call +91 75994 50220.
The honest recommendation
Do not run your own outbound mail server unless mail is your product.
Deliverability is a specialist discipline. It requires warming an IP, maintaining reputation, handling bounces and complaints, staying off blacklists and reacting when you land on one anyway. A transactional provider does all of that for a fee that is almost certainly less than the hours you would spend.
For mail on your own domain without any of that work, business email hosting runs on mail-only IPs with SPF, DKIM, DMARC and reverse DNS configured from day one — which is the entire point of buying it rather than building it.