Email deliverability guide

Port 465 vs 587 SMTP

A clear comparison of SMTP submission on ports 465 and 587, including encryption expectations and troubleshooting checks.

Already have an Inbox Warmup account? Go directly to Dashboard

A clear comparison of SMTP submission on ports 465 and 587, including encryption expectations and troubleshooting checks.

Key takeaway
Both ports are commonly used for authenticated message submission, but they normally differ in how encryption begins. Choosing the wrong encryption mode can cause connection failures even when credentials are correct.

Why port 465 vs 587 smtp matters

Both ports are commonly used for authenticated message submission, but they normally differ in how encryption begins. Choosing the wrong encryption mode can cause connection failures even when credentials are correct.

Good sending performance comes from several systems working together: a legitimate sender identity, correctly aligned authentication, a reliable connection, controlled volume, relevant recipients and fast action when warning signs appear. This guide is designed to help you review those areas in a logical order instead of changing settings randomly.

Step-by-step process

  1. Use the provider’s documented submission host — complete this check and record the result before moving to the next stage.
  2. Confirm whether the provider specifies 465 or 587 — complete this check and record the result before moving to the next stage.
  3. For 465, use implicit TLS when required — complete this check and record the result before moving to the next stage.
  4. For 587, use STARTTLS when required — complete this check and record the result before moving to the next stage.
  5. Authenticate with the correct full username — complete this check and record the result before moving to the next stage.
  6. Test relay permission for the chosen sender address — complete this check and record the result before moving to the next stage.
  7. Review firewall and hosting-provider restrictions — complete this check and record the result before moving to the next stage.

Before you begin

Make sure you control the domain, can edit DNS, can access the sending mailbox or SMTP account, and know which service actually sends the message. Keep a copy of current records before changing anything.

Before you scale

Confirm that authentication passes on real messages, connection errors are resolved, bounces are understood and sending volume is stable. Scale in measured steps rather than moving directly to a provider maximum.

  1. Identify one measurable problem.
  2. Change the smallest relevant setting or behaviour.
  3. Allow enough time for DNS or provider data to update.
  4. Retest using the same method.
  5. Keep the change only when the evidence improves.

Use a controlled improvement cycle

Record the date of each test, the domain or mailbox tested, the sending provider and the exact result. This creates a useful baseline for future troubleshooting. When performance changes, compare the new data with the last known-good configuration instead of replacing several records or providers at once.

A single passing check should not be treated as final proof that the entire sending setup is healthy. Authentication results, SMTP responses and reputation indicators should be reviewed together and compared over time. For example, SPF may pass while DKIM is missing, or an SMTP connection may succeed while the chosen From address is not authorized to relay.

How to interpret the results

What to monitor after setup

Continue reviewing the following signals after the initial configuration. A correct setup can still deteriorate when passwords change, DNS is edited, contact quality drops or campaign volume increases too quickly.

  • SPF, DKIM and DMARC results on real sent messages
  • SMTP rejection, deferral and authentication responses
  • Hard bounces, repeated soft bounces and invalid recipients
  • Complaint and unsubscribe trends
  • Changes in hourly and daily sending volume
  • Provider-specific feedback and reputation data where available
  • Meaningful replies and recipient engagement, not only open tracking

Common mistakes to avoid

  • Using port 25 for normal client submission
  • Selecting SSL for a server expecting STARTTLS
  • Assuming the login username is always the sender address
  • Ignoring certificate or hostname errors
  • Retesting passwords without checking network blocks
Important limitation: Inbox Warmup can help with controlled warmup, authentication checks and infrastructure readiness. No software can guarantee inbox placement, replies or campaign revenue. Results also depend on recipient quality, content, complaints, sending history and mailbox-provider decisions.

Useful tools for this guide

Related Inbox Warmup solutions

Frequently asked questions

Which port is better?

Use the port and encryption mode documented by your provider. Both can be secure when configured correctly.

Why does 587 connect but authentication fail?

The username, password, allowed sender, app password or tenant policy may be incorrect.

Can a hosting provider block SMTP ports?

Yes. Some networks restrict outbound SMTP, so test connectivity from the actual production server.

Recommended next step

Use the checks above to document the current state of your domain and mailbox. Fix authentication and connection errors first, then begin controlled warmup and monitor real results before increasing campaign volume.

Next step

Turn this into a controlled warmup plan.

Connect your infrastructure, verify authentication, warm up gradually and understand your reputation before scaling.