When a mail server on your own VPS refuses to send, the error almost always says which of four things is wrong: the client is not allowed to relay, authentication failed, a network path is blocked, or the receiving side does not trust your server. This guide walks through each one with commands you can run as root on a Postfix or Exim server.
Everything here assumes you run the mail server yourself, with root access. On Domain India shared and reseller hosting the mail service is managed for you, and you cannot change its configuration or read its logs. For hosting mailboxes, use Email Troubleshooting instead.
Read the exact SMTP reply first: "Relay access denied" means the sender is neither a trusted network nor authenticated; "Must issue STARTTLS" or "535" means an encryption or login problem; a timeout means a port is blocked; a 550 from Gmail or Outlook means your DNS (PTR, SPF, DKIM, DMARC) or IP reputation. Fix relay with permit_sasl_authenticated plus reject_unauth_destination, never with an open relay. Test with openssl s_client or swaks, not plain telnet.
1. Read the error before changing anything
Most relay problems can be diagnosed from the reply code alone.
| Reply | What it means | Where to look |
|---|---|---|
| 554 5.7.1 Relay access denied | The client is not authenticated and not in a trusted network, and the recipient is not local | Section 4: relay restrictions and SASL |
| 530 5.7.0 Must issue a STARTTLS command first | The server requires TLS before login | Section 5: TLS |
| 535 5.7.8 Authentication failed | Wrong username or password, or the auth backend is down | Section 4 |
| Connection timed out | A firewall, or your provider, is blocking the port | Section 3 |
| 421 or 451 temporary errors | Greylisting, rate limits or a DNS lookup failure; the mail will be retried | Mail queue and logs |
| 550 5.7.x from a big provider | The receiver rejects your server: missing PTR, SPF, DKIM or DMARC, or a blocklisted IP | Section 6 |
2. Find the log line for the failed message
The log shows the client, the reply and the reason in one line.
# Postfix on Ubuntu or Debian
sudo tail -f /var/log/mail.log
sudo journalctl -u postfix -f # if rsyslog is not installed
# Exim on Debian or Ubuntu
sudo tail -f /var/log/exim4/mainlog
# Exim on cPanel or DirectAdmin servers
sudo tail -f /var/log/exim_mainlog
# Search for relay and auth failures
sudo grep -iE "relay|sasl|auth" /var/log/mail.log | tail -50Check the queue as well: postqueue -p for Postfix, or exim -bp for Exim. A growing queue with "connection timed out" entries points to a blocked outbound port.
3. Check the network path
Two directions matter: clients reaching your server on 465 or 587, and your server reaching other mail servers on port 25.
Inbound. Open the submission ports and SMTP in your firewall. With UFW:
sudo ufw allow 25/tcp
sudo ufw allow 465/tcp
sudo ufw allow 587/tcp
sudo ufw statusUFW rules apply immediately; there is nothing to restart. If you use raw iptables or nftables instead, add the rules there and save them with your distribution's persistence tool, and do not run two firewall managers at once. See setting up a firewall on your VPS.
Outbound port 25. Many hosting and cloud providers restrict outgoing port 25 to stop spam. Test it from the VPS:
nc -zv -w 5 gmail-smtp-in.l.google.com 25If this times out while ports 80 and 443 work, outbound 25 is blocked somewhere between your VPS and the internet. On a Domain India VPS, ask support whether port 25 is open for your server. The dependable alternative is to relay through an email delivery service on port 587 (next section).
4. Fix relay permissions and authentication
A correctly configured server relays mail only for its own networks and for users who log in. Never "fix" relay access denied by turning the server into an open relay: it will be found and abused within hours, and its IP will be blocklisted.
Postfix as the server your users send through. In /etc/postfix/main.cf:
myhostname = mail.example.com
mynetworks = 127.0.0.0/8 [::1]/128
smtpd_sasl_auth_enable = yes
smtpd_sasl_type = dovecot
smtpd_sasl_path = private/auth
smtpd_sasl_security_options = noanonymous
smtpd_relay_restrictions = permit_mynetworks, permit_sasl_authenticated, reject_unauth_destinationDovecot must expose the auth socket at /var/spool/postfix/private/auth, and the submission services (587 with STARTTLS, 465 with implicit TLS) are enabled in /etc/postfix/master.cf. Keep mynetworks to localhost unless you really do trust another network.
Postfix relaying through a provider (smarthost). When outbound 25 is blocked, or you want better deliverability, send everything through an email delivery service on 587:
relayhost = [smtp.your-provider.example]:587
smtp_sasl_auth_enable = yes
smtp_sasl_password_maps = hash:/etc/postfix/sasl_passwd
smtp_sasl_security_options = noanonymous
smtp_tls_security_level = encryptPut [smtp.your-provider.example]:587 username:password in /etc/postfix/sasl_passwd, then:
sudo chmod 600 /etc/postfix/sasl_passwd
sudo postmap /etc/postfix/sasl_passwd
sudo postfix check && sudo systemctl reload postfixNote the difference: smtpd_ settings control mail coming in to your server; smtp_ settings control mail your server sends out. Mixing them up is a common cause of relay failures. For choosing a provider, see transactional email services compared.
Exim. On Debian and Ubuntu, run sudo dpkg-reconfigure exim4-config to choose "mail sent by smarthost" and set relay domains and networks; on cPanel or DirectAdmin servers use the panel's Exim settings rather than editing the file by hand, because updates overwrite manual edits. Restart with sudo systemctl restart exim4 (Debian) or sudo systemctl restart exim.
5. TLS and certificates
Modern clients and most receivers expect TLS. Point Postfix at a valid certificate, for example one from Let's Encrypt:
smtpd_tls_cert_file = /etc/letsencrypt/live/mail.example.com/fullchain.pem
smtpd_tls_key_file = /etc/letsencrypt/live/mail.example.com/privkey.pem
smtpd_tls_security_level = may
smtp_tls_security_level = mayTest the two submission styles correctly. Port 587 starts in plain text and upgrades with STARTTLS; port 465 is TLS from the first byte:
openssl s_client -starttls smtp -connect mail.example.com:587 -servername mail.example.com
openssl s_client -connect mail.example.com:465 -servername mail.example.comCheck that the certificate name matches the host name your mail app uses, and that it has not expired. To test a full authenticated send, swaks is easier than typing SMTP by hand:
swaks --to [email protected] --from [email protected] --server mail.example.com --port 587 --tls --auth LOGIN --auth-user [email protected]6. DNS and reputation
When the big providers reject or bin your mail, the relay itself works; the receiver does not trust you. Check, in this order:
- PTR (reverse DNS). The VPS IP should resolve back to your mail host name, and that name should resolve to the IP. Test with
dig -x your.ip.address. PTR records are set by whoever controls the IP, so on a Domain India VPS ask support. - SPF. One TXT record per domain, listing every sender, for example
v=spf1 mx a ip4:203.0.113.10 include:your-provider.example ~all. Two SPF records make both invalid. - DKIM. Sign outgoing mail (for example with OpenDKIM or Rspamd) and publish the public key.
- DMARC. Start with
v=DMARC1; p=none; rua=mailto:[email protected]and tighten once reports look clean. - Blocklists. A new or previously abused IP may be listed. See what to do if your email is blacklisted.
The deliverability detail is in Email Deliverability Deep-Dive.
7. Running mail on Domain India
A Domain India VPS is self-managed with full root access, so the mail server, its firewall and its configuration are yours to run. The complete mail server guide covers building one. If you would rather not operate a mail server at all, Business Email is a managed platform billed per mailbox.
- 1 vCPU
- 2 GB DDR4 RAM
- 64 GB NVMe SSD Storage
- 2 TB Monthly Bandwidth
- Priced per mailbox - start with one
- Email at your own domain ([email protected])
- Add and remove mailboxes yourself
- Webmail with calendar, contacts and tasks
Prices on the cards are Domain India list prices and exclude 18% GST.
Frequently asked questions
What does "554 5.7.1 Relay access denied" mean?
The sending client is not authenticated and not in the server's trusted networks, and the recipient is not a local domain, so the server refuses to relay. Turn on SMTP authentication in the mail app, and on the server allow relay only for authenticated users with permit_sasl_authenticated followed by reject_unauth_destination.
Should I add my network to mynetworks to fix relay errors?
Only networks you fully trust, such as localhost. Adding a wide range, or 0.0.0.0/0, turns the server into an open relay that spammers will find and abuse, and its IP will be blocklisted. Authenticate users with SASL instead.
Why does my VPS time out when sending to Gmail?
Outbound port 25 is probably blocked, either by your firewall or by the network provider. Test with nc -zv gmail-smtp-in.l.google.com 25. If it times out, relay through an email delivery service on port 587, or on a Domain India VPS ask support whether port 25 is open for your server.
Which port should mail apps use to send through my server?
Port 587 with STARTTLS or port 465 with implicit TLS, both with authentication. Port 25 is for server-to-server delivery and is blocked by many home and office internet providers.
How do I test SMTP over TLS from the command line?
For port 587 run openssl s_client -starttls smtp -connect mail.example.com:587. For port 465 run openssl s_client -connect mail.example.com:465 without the starttls option, because 465 is encrypted from the start. The swaks tool can also send a complete authenticated test message.
Can I change the mail server settings on shared hosting?
No. On Domain India shared and reseller hosting the mail server is managed for the whole server. Use the email troubleshooting guide for hosting mailboxes, and contact support if the settings are correct and mail still fails.
Ready to fix it? Start with the reply code in section 1, and if you are on shared hosting go to Email Troubleshooting. For a server-side question about your VPS, such as port 25 or reverse DNS, open a ticket in the client area or use the public ticket form. Compare plans on VPS hosting.
Tell us your VPS IP address, the mail host name and the exact error from your mail log, and we will check what can be done on our side.
Ask Domain India support