MX & SMTP guide
How MX records route email, what XGM MX & SMTP checks in DNS and over SMTP for each mail server, from STARTTLS to open relay, and how to fix mistakes.
What MX records do
When someone sends a message to anna@example.com, their mail server looks up the MX records of example.com. Each record names a mail server and a preference value. The sender tries the server with the lowest value first and moves to the next one if it cannot connect.
RFC 5321 §5.1 describes this process, including a fallback: if a domain has no MX records at all, senders try to deliver to the domain's own A or AAAA address. That fallback rarely reaches a mail server today, which is why a missing MX record is a problem even for domains that have a website.
How to use MX & SMTP
- Open MX & SMTP and enter the part after
@in an email address, for exampleexample.com. - XGM fetches the MX records and sorts them by preference.
- For up to five MX hosts, it resolves A, AAAA and CNAME records to check that each target is a usable mail server name.
- For the first three hosts, the XGM server opens an SMTP session on port 25: banner, EHLO, STARTTLS with the certificate, reverse DNS and a relay test.
- Read the findings, then continue with Run next to check SPF, DMARC or the blocklist status of the domain.
Timeouts name the server and the wait: XGM gives each server 6 seconds. A server that answers your own mail but not XGM may block the XGM network, so confirm a timeout with a message from an outside account before changing anything.
Reading MX records
example.com. 3600 IN MX 10 mx1.example.com.
example.com. 3600 IN MX 20 mx2.example.com.
mx1.example.com. 3600 IN A 192.0.2.25
mx2.example.com. 3600 IN A 198.51.100.25| Setup | Records | Behaviour |
|---|---|---|
| Primary and backup | 10 mx1, 20 mx2 | mx2 is used only when mx1 is unreachable |
| Load sharing | 10 mx1, 10 mx2 | Senders pick between equal values |
| Hosted provider | One or several provider host names | The provider handles redundancy behind the names |
| Null MX | 0 . | Domain accepts no mail (RFC 7505) |
Preference values are relative; only their order matters. 10 and 20 behave the same as 1 and 2. Hosted mailbox providers tell you exactly which records to publish, and mixing their records with old ones from a previous provider splits your mail between two systems.
What the findings mean
| Finding | Severity | Fix |
|---|---|---|
| No MX records (domain has an A record) | Warning | Publish MX records from your mail provider; the A-record fallback rarely works. |
| No MX records (no A record) | Critical | Mail to the domain cannot be delivered; publish MX records or a null MX. |
| MX points to an IP address | Critical | Use a host name with A/AAAA records (RFC 5321 §5.1). |
| Host is a CNAME | Warning | Point the MX at the canonical host name (RFC 2181 §10.3). |
| Host has no A or AAAA record | Critical | Add the address records or fix the host name. |
| Could not resolve host | Warning | Temporary lookup failure or broken delegation; check again. |
| Null MX | Info | Correct for domains that never receive mail. |
| Only one MX host | Info | Fine for large providers; self-hosted setups often add a second. |
| n mail servers resolve correctly | Passed | MX targets are usable host names. |
The SMTP test
DNS only says where mail should go. The SMTP test checks what a sending server finds when it gets there. XGM connects to each mail server on port 25 through its outbound guard, reads the greeting banner and sends EHLO to learn the supported extensions. If the server offers STARTTLS, XGM upgrades the connection, verifies the certificate against the host name and records the TLS version and cipher.
The relay test asks the server to accept a message from xgm-relay-test@example.org to xgm-relay-test@example.net, two reserved example domains that belong to nobody. A mail server must refuse that, because neither address is its own; if it answers RCPT TO with a 2xx code it is an open relay, and spammers will find it. XGM sends RSET and QUIT right after, so no message is ever sent (it never issues DATA).
| Finding | Severity | Fix |
|---|---|---|
| No mail server answered on port 25 | Critical | Check firewalls and that the MTA listens on port 25. |
| Server does not offer STARTTLS | Critical | Enable TLS with a certificate for the MX host name (RFC 3207). |
| Certificate not trusted | Warning | Use a certificate from a public CA that covers the MX host name. |
| TLS 1.0 or 1.1 negotiated | Warning | Enable TLS 1.2 and 1.3 (RFC 8996). |
| Open relay | Critical | Allow relaying only for authenticated users and your own networks. |
| No reverse DNS or PTR does not resolve back | Warning | Ask the owner of the IP block to set a PTR that matches the host name. |
| AUTH offered on port 25 | Info | Offer client logins on port 587 or 465 instead. |
Ports 465 (implicit TLS) and 587 (submission) are for mail clients, not for server-to-server delivery. XGM only tests whether they accept a TCP connection and shows the result in the table. A secure MX with a valid certificate is also what MTA-STS needs before you enforce it.
Common MX mistakes
Leftover records from an old provider
After a migration, old MX records with a higher preference value are sometimes kept "as backup". Senders that cannot reach the new provider for a moment then deliver to the old one, where nobody reads the mail any more. Remove old MX records once the migration is complete.
A backup MX that accepts everything
A secondary mail server that accepts mail for any address, without knowing which mailboxes exist, becomes a target for spammers, who deliberately use the backup to avoid the primary server's filtering. Either configure the backup with the same recipient checks and filters or rely on the sender's retry queue instead of a backup MX.
Forgetting a null MX on parked domains
Domains that are only used for websites or held defensively should publish a null MX, an SPF record of v=spf1 -all and a DMARC record with p=reject. The null MX stops senders from retrying delivery for days, and the other two stop spoofing.
example.org. IN MX 0 .
example.org. IN TXT "v=spf1 -all"
_dmarc.example.org. IN TXT "v=DMARC1; p=reject;"MX records for subdomains
MX records are not inherited. A message to alerts@status.example.com is routed by the MX records of status.example.com, not of example.com. If the subdomain has no MX but has an A record, senders fall back to that address, which is usually a web server that does not accept mail.
Decide per subdomain whether it should receive mail. Subdomains used as sender addresses for notifications often need to receive bounces and replies, so give them MX records pointing at your mail provider. Subdomains that only host websites can publish a null MX, which prevents mail to them from sitting in sender queues for days.
Check each sending subdomain with the MX Lookup as well as the main domain. A newsletter platform that sends as news.example.com with no working MX for that name loses every reply a subscriber sends.
Beyond MX: the rest of mail setup
MX records get mail to you. Whether mail from you is trusted depends on SPF, DKIM and DMARC, and whether it arrives encrypted depends on TLS on the MX hosts, optionally enforced with MTA-STS. A domain can have perfect MX records and still have its outgoing mail rejected.
- SPF guide: which servers may send for the domain.
- DMARC guide: what receivers do with unauthenticated mail.
- MTA-STS guide: requiring TLS for mail delivered to your MX hosts.
- Deliverability checklist: everything that affects inbox placement.
FAQ
What does the MX preference number mean?
Senders try the lowest number first. Equal numbers share load. The actual values do not matter, only their order.
Can an MX record point to an IP address?
No. MX targets must be host names that have A or AAAA records. An IP address in an MX record is invalid, and many senders will not deliver to it.
Can an MX host be a CNAME?
It should not be. RFC 2181 says MX targets must not be aliases. Many senders still follow the alias, but some do not, so point the MX at the canonical name.
What is a null MX?
An MX record with preference 0 and target ., defined in RFC 7505. It tells senders the domain accepts no mail, so they return a bounce immediately.
Do I need two MX records?
Not with large hosted providers, whose host names are backed by redundant infrastructure. Self-hosted mail often uses a second MX, which must filter as well as the primary.
How long do MX changes take?
As long as the TTL of the old records. Sending servers also retry failed deliveries, so mail during a change is usually delayed rather than lost.
Does the SMTP test send an email?
No. It connects, reads the banner, upgrades with STARTTLS and tests relaying with MAIL FROM and RCPT TO, then resets and quits before DATA, so no message is transferred.