Whenever you configure an email client, a WordPress SMTP plugin, a server mail agent (like Postfix), or an application framework (like Laravel or Django), you are asked to specify an SMTP Port.
The four common numbers you encounter are 587, 465, 25, and occasionally 2525. Choosing the wrong port can result in connection timeouts, certificate mismatches, or silent email drop-offs.
In this guide, we demystify each port, explain the cryptographic difference between STARTTLS and implicit SSL/TLS, and help you select the exact port to ensure your emails reach the inbox without interruption.
Quick Answer: Which SMTP Port Should I Use?
- Port 587 (Recommended): Use Port 587 with STARTTLS for almost all modern web applications, WordPress plugins, APIs, and mail clients. It is the universal standard defined in RFC 6409 for email submission.
- Port 465 (Alternative): Use Port 465 if your software requires implicit SSL/TLS from the initial socket connection (e.g., SMTPS).
- Port 25 (Do Not Use for Client Apps): Reserved strictly for server-to-server MTA relaying. Most residential ISPs and cloud providers (AWS EC2, Google Cloud, DigitalOcean) block outbound port 25 by default to prevent spam.
- Port 2525 (Fallback): An alternate consumer port supported by some relays when ports 587 and 465 are restricted by firewalls.
Deep Dive: Breaking Down Each SMTP Port
1. Port 587: The Modern Submission Standard (STARTTLS)
In 1998, RFC 2476 formally separated email submission (a user or application handing an email to an outgoing server) from email relay (servers communicating between each other). Port 587 was designated as the default port for email submission.
Port 587 uses STARTTLS (opportunistic TLS upgrade). When your client connects to port 587, the connection starts in cleartext. Your client issues the command STARTTLS, and the server immediately upgrades the existing TCP socket to an encrypted TLS session before any login credentials or message content are exchanged.
Pros: Supported by virtually every modern email provider and client. Not blocked by consumer ISPs or cloud hosts.
2. Port 465: Implicit TLS / SMTPS
In the late 1990s, IANA originally registered Port 465 for SMTPS (SMTP over SSL), mirroring HTTPS on port 443. Although it was briefly deprecated in favor of STARTTLS on port 587, RFC 8314 in 2018 formally reinstated Port 465 as a recommended port for secure message submission.
Unlike port 587, Port 465 is implicitly encrypted. The SSL/TLS handshake occurs immediately upon establishing the TCP socket, before any SMTP commands (like EHLO) are sent. If the TLS handshake fails, the connection closes immediately.
Pros: Zero risk of downgrade attacks (since cleartext is never used, even for a single packet).
3. Port 25: The Server-to-Server Relay
Port 25 is the original SMTP port established in RFC 821 in 1982. It remains the backbone of the global internet for server-to-server mail exchange (for example, when Mailofly's outbound servers transmit an email to Google's aspmx.l.google.com servers).
However, because rogue botnets historically used port 25 to blast millions of unauthenticated spam emails from infected home computers, almost every internet service provider (ISP) and major cloud platform (AWS EC2, Google Cloud, Azure, DigitalOcean) blocks outbound traffic on port 25 for consumer and cloud accounts.
Verdict: Never configure client applications or website contact forms to use Port 25.
STARTTLS (Port 587) vs. Implicit TLS (Port 465)
Understanding the difference between STARTTLS and implicit TLS prevents common configuration errors:
| Feature | Port 587 (STARTTLS) | Port 465 (Implicit TLS) |
|---|---|---|
| Initial Handshake | Plaintext TCP, then upgraded via STARTTLS |
Encrypted TLS from the first byte |
| RFC Specification | RFC 6409 | RFC 8314 |
Nodemailer secure flag |
secure: false |
secure: true |
| WordPress SMTP Encryption | Select TLS |
Select SSL |
| ISP Blocking Risk | Extremely Low | Extremely Low |
How to Configure Mailofly SMTP
When connecting to the Mailofly SMTP Relay, use the following standardized settings:
- SMTP Host:
smtp.mailofly.com - Port:
587(STARTTLS) or465(SSL/TLS) - Authentication: Required
- Username:
apikey - Password: Your Mailofly API Key (
mf_live_...)
WordPress (WP Mail SMTP / FluentSMTP) Example
Mailer: Other SMTP
SMTP Host: smtp.mailofly.com
Encryption: TLS
SMTP Port: 587
Authentication: On
SMTP Username: apikey
SMTP Password: [Your Mailofly API Key]
Nodemailer (Node.js) Example
import nodemailer from "nodemailer";
// Using Port 587 with STARTTLS
const transporter = nodemailer.createTransport({
host: "smtp.mailofly.com",
port: 587,
secure: false, // true for port 465, false for 587
auth: {
user: "apikey",
pass: process.env.MAILOFLY_API_KEY,
},
});
Testing Your SMTP Connection
If your application reports connection timeouts, run a quick network probe using OpenSSL to verify that your firewall isn't blocking the port:
# Test Port 587 with STARTTLS
openssl s_client -starttls smtp -crlf -connect smtp.mailofly.com:587
# Test Port 465 with direct TLS
openssl s_client -crlf -connect smtp.mailofly.com:465
You can also verify your server's reverse DNS setup using our free Reverse DNS Lookup Tool.
Summary
In 2026, the golden rule of SMTP ports is straightforward:
- Use Port 587 with STARTTLS as your default choice for all applications and plugins.
- Use Port 465 with SSL/TLS if your client specifically requires implicit SSL.
- Avoid Port 25 for application email submissions.
Need an enterprise-grade SMTP relay with automated DKIM/SPF alignment, 99.99% uptime, and 30-day logs? Check out the Mailofly Universal SMTP Relay or start sending via the Mailofly REST Email API today.



