# What Is an SMTP Relay and When Do You Need One? URL: https://warmerly.com/blog/what-is-smtp-relay Published: 2026-10-04 Reading time: 7 minutes Tags: Transactional email, SMTP, Deliverability > An SMTP relay accepts your app's email and delivers it for you. How it works, ports 25, 465 and 587, SPF and DKIM setup, and when an API is the better choice. An SMTP relay is a mail server that accepts an email from your application, website or device over SMTP and delivers it to the recipient's mail server for you. Your software never has to find the recipient's server, retry a failed delivery or build a sending reputation of its own: the relay does all three. You connect to it with a hostname, a port, and a username and password (or an API key used as the password). ## How an SMTP relay works 1. Your app connects to the relay's SMTP server and authenticates, so the relay knows the mail is yours and not a stranger's. 2. It hands over the message: the sender address, the recipients, the subject and the body. 3. The relay looks up each recipient domain's MX record, connects to that mail server and delivers the message, retrying later if the server says to try again. 4. If a delivery fails for good (the address does not exist, or the recipient's server rejects it), a well-run relay records the bounce and stops sending to that address. That is the whole job. A relay is not a mailbox: it does not store mail for people to read. A mail server with mailboxes (Gmail, Microsoft 365) receives and stores email; a relay only sends it on. ## Which port to use | Port | Used for | Notes | | --- | --- | --- | | 587 | Authenticated submission | The standard choice for a relay. Starts as plain text and upgrades to TLS with STARTTLS. | | 465 | Authenticated submission over implicit TLS | Encrypted from the first byte. Fine where a client only supports it. | | 2525 | An alternative submission port | Offered by some providers for networks that block 587. Check that yours supports it. | | 25 | Server-to-server delivery | Not for apps. Many hosting and cloud providers block or throttle outbound port 25 by default. | ## Why use a relay instead of sending from your own server - Delivery is the hard part. Inbox providers judge mail by the sending IP and domain, and a relay's established IPs and feedback loops are something a fresh server does not have. - Outbound port 25 is often blocked on cloud hosts, so a server of your own may not be able to reach recipients at all. - Retries, bounce handling and suppression are built in, so you do not write that code. - Your own server's IP is not exposed to blocklists when something goes wrong. ## What to set up so the mail is trusted A relay delivers the mail, but the receiving server decides whether to believe it. Three DNS records on the domain in your From address decide that: - SPF lists which servers may send for your domain. Add the relay's include to your record, and keep to one SPF record with no more than ten DNS lookups. - DKIM signs each message so the receiver can check it was not altered. The relay gives you the records to publish, usually CNAMEs. - DMARC tells receivers what to do when SPF and DKIM fail to line up with your From domain. Start with p=none and a reporting address, then tighten it once the reports look clean. Gmail and Yahoo require SPF or DKIM from every sender, and DMARC with alignment from anyone sending in bulk. You can check your records for free with the SPF checker, the DKIM checker and the DMARC checker. **Check your domain** - [SPF checker: is your record valid and under the lookup limit?](https://warmerly.com/spf-checker) - [DKIM checker: is your signing key published?](https://warmerly.com/dkim-checker) - [DMARC checker: is your policy set and aligned?](https://warmerly.com/dmarc-checker) - [Free deliverability checker: the whole domain in one pass](https://warmerly.com/deliverability-checker) ## SMTP relay or an email API? Most email providers offer both. They end up in the same place, but they are used differently. | | SMTP relay | Email API | | --- | --- | --- | | How you send | A mail library speaks SMTP to the relay | An HTTPS request with a JSON body | | Works with | Anything that can send SMTP: WordPress, CMS plugins, printers, legacy apps | Code you write or can change | | Errors | Reported by SMTP reply codes, often after the fact | Returned straight away in the response | | Extras | Whatever the provider adds on top | Usually richer: tags, templates, per-message status, webhooks | Use an SMTP relay when the software you are connecting only knows how to send through SMTP, or when you are moving an existing app and want the smallest change. Use an API for new code, where the immediate, structured response is easier to work with. ## Choosing a provider - Check that it offers SMTP at all: some providers are API only. - Look at what the plan includes at your monthly volume, and what overage costs, using the provider's own pricing page. - Check how long it keeps logs and how it handles bounces and complaints. - Ask whether a dedicated IP is available if you send a lot. > **Where Warmerly fits** — Warmerly's transactional email is an HTTPS API that sends through Amazon SES. It does not offer an SMTP relay yet, so if your software can only send through SMTP, choose a provider that does. If you are writing the sending code yourself, the API is a single request. **Compare transactional email providers** - [Warmerly transactional email API](https://warmerly.com/transactional-email) - [Mailgun alternative: prices at four volumes](https://warmerly.com/transactional-email/mailgun-alternative) - [Amazon SES alternative: SES without the plumbing](https://warmerly.com/transactional-email/amazon-ses-alternative) - [SendGrid alternative](https://warmerly.com/transactional-email/sendgrid-alternative) ## Open relays: the mistake to avoid A relay that accepts mail from anyone, with no authentication, is called an open relay. Spammers find and abuse them within hours, and the server's IP ends up on blocklists. If you run your own relay, require authentication, restrict who may connect, and never leave it open to the internet. If you use a provider's, the authentication is already handled. --- Source: https://warmerly.com/blog/what-is-smtp-relay Full content index: https://warmerly.com/llms-full.txt Site index: https://warmerly.com/llms.txt