Skip to content
Hosting Operations8 min read

Port 25 Blocked VPS: 4 Options Compared [2026]

Compare port 25 unblock requests, SMTP relays, alternate ports, and workarounds. Find the fastest fix for your VPS mail setup.

Written by Abdul AbrorTechnical Hosting Support Engineer
a rack of electronic equipment in a dark room
On this page

TL;DR — Key takeaways

  • Port 25 is blocked by default on most VPS providers to prevent spam; unblock requests succeed only with proven mail volume and reputation history.
  • SMTP relay services on port 587 deliver mail immediately without waiting for provider approval and cost $10-35/month for typical business volumes.
  • Requesting port 25 unblock takes 24-72 hours and requires reverse DNS, SPF records, and a credible use case; denials are common for new accounts.
  • Running your own mail server on port 25 after unblock gives full control but requires ongoing spam monitoring, blacklist management, and security maintenance.

Port 25 is blocked on nearly every VPS by default. The block stops direct SMTP connections between your server and recipient mail servers, breaking outbound email unless you take one of four paths: request an unblock, relay through port 587, switch ports entirely, or move providers.

Each option has trade-offs in speed, cost, control, and maintenance burden. I've handled hundreds of support tickets on this exact issue. The right choice depends on your mail volume, technical capacity, and whether you need to own the entire mail stack or just get messages delivered.

Why Port 25 Is Blocked and How to Verify

Cloud providers block port 25 to stop spam at the infrastructure level. A single compromised VPS can send millions of spam emails in hours, landing the provider's entire IP range on blacklists. Blocking port 25 outbound prevents that damage before it starts.

Test the block from your VPS by running telnet smtp.gmail.com 25. If the connection times out or you see "Connection refused," port 25 is filtered. A successful connection shows a 220 greeting from Gmail's server. You can also try telnet mx1.mail.com 25 or any other public mail server.

The block happens at the hypervisor or network firewall, not in your VPS firewall rules. Adding an iptables rule to allow port 25 does nothing because the traffic never reaches your instance. Check your provider's documentation under "SMTP" or "port 25" for official policy.

Option 1: Request Port 25 Unblock from Your Provider

Requesting an unblock is free but slow and often denied. You submit a ticket explaining your use case—transactional emails, newsletters, customer notifications—and the provider reviews your account age, payment history, and technical setup.

Approval requirements vary by provider. AWS requires a reverse DNS record and a form explaining your mail volume. DigitalOcean checks account standing and may ask for domain verification. Google Cloud reviews manually and denies most new accounts. Expect 24 to 72 hours for a response.

If approved, you get unrestricted port 25 access and can send mail directly to recipient servers. This gives full control over delivery timing, retry logic, and bounce handling. You also inherit full responsibility for spam filtering, security patches, and blacklist monitoring.

Denied requests usually point you to SMTP relay services. Providers rarely explain the denial reason in detail. You can reapply after building sender reputation, but repeated denials are common for accounts under six months old or with low activity.

  • Best for: Established businesses with existing mail infrastructure and technical staff to manage it
  • Approval rate: 30-50% for new accounts, higher for accounts over one year with clean payment history
  • Cost: Free, but operational overhead includes monitoring, security, and blacklist management
  • Time to delivery: 24-72 hours for approval, then immediate sending capability

Option 2: Use an SMTP Relay Service on Port 587

SMTP relays bypass the port 25 block entirely. Your application connects to the relay on port 587 with authentication, and the relay delivers mail on port 25 from its own IP addresses with established reputation.

Services like SendGrid, Mailgun, Amazon SES, and Mailgun offer free tiers for low volume (100-1,000 emails per day) and charge $10-35/month for typical business use. Setup takes under an hour: create an account, grab SMTP credentials, update your mail transfer agent config, and send a test message.

Relays handle delivery queues, bounce processing, and reputation automatically. They also provide delivery analytics and webhook integrations for tracking opens and clicks. The trade-off is vendor lock-in and per-message pricing at higher volumes.

Port 587 is the submission port, designed for authenticated client-to-server connections. It's open on all VPS providers because it requires credentials and can't be abused for direct spam injection the way port 25 can.

  • Best for: Most users—fastest path to working email without infrastructure overhead
  • Approval rate: Instant; no provider permission required
  • Cost: $0-10/month for under 10k emails; $20-100/month for 50k-500k emails
  • Time to delivery: 15-60 minutes for initial setup, then immediate sending

Option 3: Use Alternate Ports (465, 2525) with Relay

Port 465 (SMTPS) and port 2525 are also used for mail submission to relays, not direct delivery. Like 587, they require authentication and connect to a relay service, not to recipient mail servers.

Port 465 was briefly deprecated in favor of 587 with STARTTLS, but it's back in standard use for implicit TLS connections. Port 2525 is a non-standard alternative some relays offer when 587 is blocked by aggressive firewalls. Neither port lets you deliver mail directly; both require a relay.

These ports don't solve the port 25 block—they're just alternate paths to the same relay solution. Use them if your network blocks 587 or if your relay provider recommends them, but they're functionally identical to the port 587 approach above.

Option 4: Switch to a Provider That Allows Port 25

Some VPS providers leave port 25 open by default or unblock it on request with minimal friction. Smaller hosting companies and dedicated server providers often have lighter restrictions than the major clouds.

OVH, Linode (for older accounts), and Vultr have historically been more permissive, though policies change. Dedicated servers from Hetzner or wholesale providers usually ship with port 25 open. Check current policy before migrating; don't assume based on outdated forum posts.

Switching providers for port 25 access alone is drastic. Factor in migration effort, downtime risk, and whether your application architecture depends on provider-specific services. If you're already planning a move, mail policy can be a secondary consideration.

  • Best for: Users already committed to self-hosting mail infrastructure with strong technical background
  • Approval rate: Varies by provider; some open by default, others require justification
  • Cost: Equivalent to current VPS cost, plus migration time
  • Time to delivery: Days to weeks for migration, then immediate sending

Comparison Summary and Recommendation

For 80% of use cases, an SMTP relay on port 587 is the right answer. It's fast, reliable, and removes mail server maintenance from your workload. Unless you're sending over 500k emails per month or need full control over retry logic for compliance reasons, a relay beats self-hosting on cost and time.

Request a port 25 unblock if you already run a mail server, have staff to maintain it, and your provider is likely to approve based on account age. Don't request an unblock just to avoid a $15/month relay bill—the operational overhead of managing your own mail server costs more in time.

Switching providers makes sense only if you're already dissatisfied or if mail is a core product feature requiring full stack ownership. Migration risk and effort outweigh the benefit unless other factors are pushing you to move anyway.

In support tickets I handled, the usual mistake was underestimating mail server complexity. Operators requested port 25, got it approved, then spent weeks troubleshooting SPF, DKIM, DMARC, and blacklist removals. Start with a relay. Migrate to self-hosting later if volume and need justify it.

Testing After Unblock or Relay Setup

After port 25 is unblocked or relay credentials are configured, send test messages to multiple providers: Gmail, Outlook, Yahoo, and a self-hosted domain if available. Check both inbox and spam folders.

Watch your mail logs for bounce codes. 550 errors mean the recipient server rejected your message—usually due to missing SPF or DKIM records. 451 errors are temporary; the recipient is throttling or greylisting you. 554 errors often mean you're on a blacklist.

Use mail-tester.com or mxtoolbox.com to check your DNS records and test deliverability. Both tools send a test message and score your configuration. Aim for 8/10 or higher before sending production mail.

If you're using a relay, verify that your application is actually routing through it. Grep your mail logs for the relay hostname. If you see direct delivery attempts to recipient MX records, your config didn't take effect.

Quick troubleshooting checklist

  • Test current port 25 status with telnet smtp.gmail.com 25 from your VPS
  • Check provider documentation for port 25 unblock request process and eligibility requirements
  • Set up SPF, DKIM, and reverse DNS records before submitting unblock request
  • Configure SMTP relay credentials in your application or mail transfer agent
  • Send test emails and verify delivery in recipient spam folders
  • Monitor mail logs for 451 or 550 relay errors after configuration changes

FAQ

Why do VPS providers block port 25 by default?

Port 25 is blocked to prevent spam. New VPS instances have no sender reputation, and open port 25 access lets compromised servers send thousands of spam emails before detection. Providers block it globally to protect their IP reputation and avoid landing on public blacklists that would affect all customers.

Can I use port 587 instead of port 25 for sending email?

Port 587 works for submission to an SMTP relay but not for direct server-to-server delivery. Your application can send to a relay service like SendGrid or Mailgun on port 587 with authentication, and the relay delivers to recipients on port 25. This bypasses the VPS block entirely.

How long does a port 25 unblock request take?

Most providers respond within 24 to 72 hours. AWS and Google Cloud require a support ticket with justification. DigitalOcean reviews account age and payment history. Approval is not guaranteed; new accounts and small-volume senders are frequently denied and directed to use relay services instead.