SMTP Test
Enter a domain and the tool opens a short SMTP session to its lowest-priority-number MX hosts. It reads the greeting and the EHLO reply, then says goodbye. It never sends a message.
Run SMTP banner and EHLO check
No sign-up required. Public hosts and addresses only; results show what was observed, nothing is simulated.
What this test does
SMTP (RFC 5321) is the protocol servers use to hand mail to each other. A session begins with the server's 220 greeting. The client answers with EHLO, and the server replies with a list of extensions it supports, such as STARTTLS, SIZE and PIPELINING. This tool looks up the domain's MX hosts, connects to at most three of them on port 25, and records the greeting and extension list.
The commands sent are EHLO and QUIT and nothing else. The test sends no mail, makes no MAIL FROM or RCPT TO request, never attempts AUTH, and does not use VRFY or EXPN. It does not probe whether a particular recipient address exists.
How to read the result
The reachability row says how many hosts answered with a 220 greeting. The greeting row shows what the server announces about itself, and the banner finding notes if the text discloses software names or versions. Disclosure is informational: it is not a vulnerability by itself, but it tells outsiders what you run.
The capability table lists extensions as advertised by each host. STARTTLS in that list means the server offers to upgrade the connection to TLS; it does not show that the certificate is valid or that senders will insist on it, which is the job of the STARTTLS checker. If VRFY or EXPN is advertised the tool notes it, because those commands can reveal valid mailbox names, but it does not run them.
Common problems
- No host answered. The server may be down, listening on a different port, or blocking this scanner's address. The result is reported as unknown for those cases rather than as a faulty server.
- Outbound port 25 is blocked from the scanner. The tool first runs an egress check. If the check fails the tool says it could not test anything, and the result says nothing about your servers.
- Connection accepted but no greeting. Some systems delay or tarpit the greeting deliberately; a timeout is not proof of failure.
- STARTTLS not advertised. Mail on those connections would travel in plaintext when the sender permits it.
- A code other than 220 in the greeting. Codes such as 421 or 554 mean the server is refusing the session from this scanner, which may reflect a reputation or rate rule rather than a fault.
- Greylisting or reputation blocks. Some servers refuse unfamiliar clients, so results can differ from another network.
How to fix issues safely
Prerequisites: administrative access to the mail server or the provider's control panel, and an understanding of whether the host is a managed service. For hosted mail you usually cannot change banners or extensions yourself; raise it with the provider. Operational risk: firewall and TLS changes on a mail server interrupt inbound mail if wrong. Rollback: take a configuration backup and make one change at a time.
- Confirm the MX names are the ones you expect using the mail server diagnostics first.
- If nothing answers, check that the service listens on TCP port 25 and that a firewall allows inbound connections from the public internet.
- If STARTTLS is missing, enable it in the mail server configuration with a valid certificate before any other change.
- If you wish to reduce banner disclosure, change the greeting text in the server settings.
- Re-run the test and confirm the greeting and capability list.
What this test cannot show
It uses a single vantage point, so a firewall, geo block or greylist may behave differently for other senders. Only up to three MX hosts are tested, chosen by lowest preference number. It cannot demonstrate that a message would be accepted, that a mailbox exists, that submission ports 587 or 465 work, or that authentication is safe. Open relay testing, user enumeration and credential checks are intentionally excluded.
Frequently asked questions
Does the SMTP test send an email?
No. It sends only EHLO and QUIT after reading the greeting. No message, sender, recipient or authentication command is issued.
Will it check whether a mailbox exists?
No. The tool does not issue RCPT TO, VRFY or EXPN, so it does not probe recipients.
Why does it test only some of my MX hosts?
To keep the test bounded, it tests at most three hosts, starting with the lowest preference numbers.
Why did it say port 25 could not be tested?
The scanner checks that it can reach port 25 at all. If outbound connections are blocked from its network, the result describes the scanner, not your server.
Is a banner that shows the software name a problem?
It is information disclosure of low significance. Changing it is optional hardening and does not replace patching.
Does STARTTLS advertised mean my mail is encrypted?
Not necessarily. Senders may ignore the offer, and nothing here validates the certificate.
Scope of this tool
- Only EHLO and QUIT are sent; no AUTH, VRFY, EXPN, MAIL, RCPT or DATA.
Written by DNS Tools editorial · Last updated 2026-10-09