Your application tries to send email through an outside SMTP server, such as Microsoft 365 or Gmail, and fails with Connection timed out (110). The message is the same whatever the cause, so the useful work is finding out which layer drops the connection: the firewall, IPv6 routing, PHP or the application's settings. This guide covers what you can check on shared hosting and, separately, how to debug it on a cPanel server you run yourself with the CSF firewall.
A timeout means packets are being dropped, usually by an outbound firewall or a broken IPv6 route; "connection refused" and authentication errors are different problems. On Domain India shared hosting you can't see or change the server firewall, and on our cPanel servers PHP's socket functions are disabled, so SMTP from PHP won't work there: send with mail() and -f, or an email API over HTTPS, and open a ticket if you need the network side checked. On your own server, test with nc and openssl over IPv4 and IPv6, check the firewall's outbound SMTP rules, fix IPv6 rather than switching it off, and never disable TLS certificate checks in your app.
1. Read the error first
| What you see | What it usually means |
|---|---|
| Connection timed out (110) | Packets are dropped: an outbound firewall rule, or an IPv6 address with no working route |
| Connection refused (111) | The host answered but nothing listens on that port, or the port is wrong |
| Network is unreachable (101) | No route at all, often an IPv6 address on a server without IPv6 |
| has been disabled for security reasons | A PHP function the library needs is switched off; this is not a network problem |
| 535 or Could not authenticate | The connection works; the username, password or authentication method is wrong |
Fix the error you actually have: a firewall change fixes neither an authentication failure nor a disabled function.
2. On Domain India shared hosting
On shared hosting (cPanel, DirectAdmin or Webuzo), the firewall belongs to the server, not your account. You can't view its rules, and neither CSF nor its logs are visible from your panel. What you can do:
- Check for a disabled-function error first. On our cPanel servers,
fsockopen,stream_socket_clientandsocket_createare disabled, so PHPMailer in SMTP mode, Laravel's SMTP mailer and SMTP plugins can't open a connection at all. On DirectAdmin, test on your plan. See PHP disabled functions on shared hosting. - Use the route that works. PHP
mail()with the-fenvelope sender sends through the server's own mail system; PHPMailer can build the message and hand it tomail(). An email provider's HTTPS API is the other option. Both are explained in Sending email from PHP and How to use PHPMailer for contact forms. - Watch your limits. Outgoing mail is limited to 200 messages per hour per account on cPanel and 1,000 per day on DirectAdmin.
- Ask us to check the network side. If you still get a timeout, open a ticket with the SMTP host and port you are connecting to, the exact error, and the time it happened. Don't try to work around the server firewall.
If your application must send through an outside SMTP server, run it where you control the network: a VPS or the App Platform.
The rest of this guide is for your own server with root access.
3. Own server: test the network path
Test from the server itself, over IPv4 and IPv6 separately:
nc -vz -4 -w 10 smtp.office365.com 587
nc -vz -6 -w 10 smtp.office365.com 587If IPv4 connects and IPv6 times out, the problem is IPv6 routing (section 5). If both time out, suspect the firewall (section 4). If the host doesn't resolve, check DNS with dig +short smtp.office365.com before anything else.
Then check that STARTTLS and the certificate work:
openssl s_client -starttls smtp -connect smtp.office365.com:587 -brief </dev/nullswaks goes one step further and runs a full test send with authentication, which shows the exact SMTP reply if the login fails.
4. Own server: check the firewall
On a cPanel server with CSF, three things commonly block outbound SMTP:
- SMTP_BLOCK. When it is on, only root and the mail server may make outgoing SMTP connections; scripts running as ordinary users are dropped.
SMTP_ALLOWUSERandSMTP_ALLOWGROUPexempt named users. - Outbound port rules. If the submission port is not in the outbound allowed list, connections to it are dropped.
- Deny entries.
csf -g 587andcsf -g PROVIDER_IPshow which rules match.
Letting every account connect to any mail server on the internet is how a single hacked website turns a server into a spam source. Prefer one of these, in order: send through the server's own mail server and configure it to relay through your provider (a smarthost); use the provider's HTTPS API; or allow only the specific system user that needs it. Large providers such as Microsoft 365 and Gmail use many changing IP addresses, so allow lists built from IPs go stale.
After changing CSF, reload it with csf -r and repeat the nc test. Note that ConfigServer stopped developing CSF in 2025. For a new server, use firewalld, ufw or nftables with fail2ban instead; the same principle applies: allow outbound SMTP for the mail server, not for every user.
5. IPv6: fix the route, don't switch it off
Many providers publish IPv6 addresses. If your server has an IPv6 address but no working IPv6 route, connections try IPv6 first and hang. Check:
ip -6 route show default
curl -6 -sI https://www.google.com | head -1If there's no default route or the test fails, fix the IPv6 configuration with your host. Until then, you can make the system prefer IPv4 for outgoing connections by adding this line to /etc/gai.conf:
precedence ::ffff:0:0/96 100This keeps IPv6 available for services that use it, unlike disabling IPv6 with sysctl, which can break services listening on IPv6 and hides the real fault.
6. Own server: test from PHP
A command-line test can pass while PHP still fails, because PHP-FPM may run as a different user and CSF's SMTP_BLOCK applies to that user. Test as the site's user:
<?php
$host = 'smtp.office365.com';
$port = 587;
$ctx = stream_context_create(['socket' => ['bindto' => '0:0']]); // force IPv4 for this test
$fp = @stream_socket_client("tcp://$host:$port", $errno, $errstr, 10, STREAM_CLIENT_CONNECT, $ctx);
echo $fp ? "Connected\n" . fgets($fp) : "Failed: $errstr ($errno)\n";Run it with sudo -u SITEUSER php test-smtp.php, then delete the file. If it connects from the command line but times out here, the firewall is treating that user differently.
7. Laravel settings
Keep the configuration simple and keep TLS verification on:
MAIL_MAILER=smtp
MAIL_HOST=smtp.office365.com
MAIL_PORT=587
[email protected]
MAIL_PASSWORD=your-password
MAIL_FROM_ADDRESS="[email protected]"
MAIL_FROM_NAME="${APP_NAME}"On port 587 the mailer negotiates STARTTLS by itself. Older Laravel versions also use MAIL_ENCRYPTION=tls; newer ones use MAIL_SCHEME instead; follow the config/mail.php of your version. After any change run php artisan config:clear and, if you use queues, php artisan queue:restart.
Old guides suggest verify_peer => false. That lets anyone on the network path read your mail password. If the certificate check fails, fix the cause: the server's CA bundle, the hostname you connect to, or the clock.
Microsoft is also retiring basic (password) authentication for SMTP in Exchange Online. If Microsoft 365 rejects a correct password, check Microsoft's current guidance; a transactional email provider or OAuth may be needed.
8. Where Domain India fits
On Domain India shared hosting, PHP mail() with -f works without setup, and support checks the server side for you. For apps that need outside SMTP, a Domain India VPS gives you root access and control of the firewall; VPS plans are self-managed. The App Platform runs apps in containers where SMTP libraries work normally. Compare VPS plans and the App Platform.
- 1 vCPU
- 2 GB DDR4 RAM
- 64 GB NVMe SSD Storage
- 2 TB Monthly Bandwidth
Prices on the cards exclude 18% GST.
What does SMTP "Connection timed out (110)" mean?
The connection attempt got no reply, so packets are being dropped somewhere, usually by an outbound firewall rule or a broken IPv6 route. It is different from "connection refused", which means the host answered but nothing listens on that port.
Can I see or change the CSF firewall on Domain India shared hosting?
No. The firewall belongs to the server and isn't visible from your control panel. Open a ticket with the SMTP host, port, exact error and time, and support will check the server side.
Why does PHPMailer or Laravel SMTP fail on Domain India cPanel hosting?
The socket functions SMTP needs, such as fsockopen and stream_socket_client, are disabled on our cPanel servers. Send with PHP mail() and the -f envelope sender, or through an email provider's HTTPS API.
Should I disable IPv6 to fix SMTP timeouts?
No. Check whether the server has a working IPv6 route and fix it. Until then, prefer IPv4 through /etc/gai.conf, which keeps IPv6 available for other services.
Is it safe to set verify_peer to false in Laravel mail settings?
No. It turns off the check that you are talking to the real mail server, so your password can be intercepted. Fix the certificate problem instead.
How do I allow outbound SMTP safely on my own server?
Let only the mail server make outbound SMTP connections and have it relay through your provider, or use the provider's HTTPS API. Avoid opening outbound SMTP for every user on the server.
Ready to get your mail flowing? Read Sending email from PHP for shared hosting, Troubleshooting SMTP relay issues on a VPS for your own server, or open a support ticket with the error you see.
Send us the SMTP host, port, exact error and the time it happened, and we will check the server side with you.
Open a support ticket