MX Lookup and SMTP Test
Check a domain's mail servers and test SMTP connections, STARTTLS and open relay.
Related tools
- Email SecurityCheck SPF, DKIM, DMARC, MTA-STS, TLS-RPT and BIMI for a domain and get the records to fix them.
- Blacklist CheckerCheck whether an IP address or a domain's mail server is listed on DNS blocklists.
- DNS LookupLook up DNS records by type, including reverse (PTR) lookups for IP addresses.
- Domain HealthOne check for DNS, email authentication, TLS, security headers and redirects, with a grade per area and a full report.
About this tool
MX & SMTP reads a domain’s MX records, resolves each mail server, and then connects to the first three of them from the XGM server to see what a sending mail server sees: the banner and EHLO extensions on port 25, the STARTTLS handshake and the certificate behind it, the reverse DNS of the address, and whether the server relays mail for outside senders. Ports 465 and 587 are tested the same way, including which AUTH mechanisms are offered before TLS is up. The records themselves are judged against the rules senders apply - an MX target must be a hostname with an address record and not a CNAME (RFC 2181 section 10.3), and a lone “0 .” record is the null MX of RFC 7505. The session always stops before DATA and never authenticates, so no message is sent and no mailbox is probed. It does not verify whether an individual address exists, read mail, or test inbound filtering or spam scoring.
XGM resolves the MX records, then connects to up to three mail servers on port 25 from its server: it reads the banner, sends EHLO, upgrades with STARTTLS and checks the certificate, and tests relaying with an outside sender and recipient (RFC 2606 example domains). It stops before DATA, so no message is ever sent. On ports 465 (implicit TLS) and 587 (STARTTLS) it reads the banner, the TLS version and certificate, the EHLO extensions and AUTH mechanisms before and after TLS, and never tries to log in. Each step is timed. In the same run it checks the first IPv4 address of each mail server (at most five) against the 58 IP blocklists of the blacklist tool; the Blocklists column links to the full result, and an address whose lookups failed is shown as not checked, never as not listed.
How to use it
- Open the MX & SMTP tool.
- Enter the public domain, hostname or IP address you want to check.
- Run the check; XGM queries it from its server and lists the findings.
- Copy the output only after checking it looks correct.
- Use related XGM tools if you need a broader diagnostic view.
FAQ
What does “Port 25 could not be tested from the XGM server” mean?
It appears when no mail server answered on port 25 while the same hosts answered on 465 or 587. Many hosting providers block outgoing port 25 from their networks, so the silence is most likely on the XGM side and says nothing about your servers. The 465 and 587 results in the same run are real; confirm port 25 by sending a message from an outside account.
Does the open relay test actually send an email?
No. It issues MAIL FROM and RCPT TO with addresses in the RFC 2606 example domains - xgm-relay-test@example.org to xgm-relay-test@example.net - then sends RSET and quits, so DATA is never reached and no message body exists. A server that accepts that RCPT TO with a 2xx code is relaying for a stranger, which is why the finding is critical.
My MX points at a CNAME and mail still arrives. Why is it flagged?
RFC 2181 section 10.3 requires the target of an MX record to be a canonical hostname with its own address records, not an alias. Most senders resolve the alias anyway, but some reject the domain outright, and the failure is intermittent and hard to trace. Point the MX at the name the CNAME resolves to, which the finding shows.
What is a null MX and when should I publish one?
A single MX record with preference 0 and a target of “.”, defined in RFC 7505, tells senders that the domain accepts no mail so they fail immediately instead of queueing for days. Publish it for domains that only host a website or are parked. XGM reports it as informational, not as a fault.
The certificate is reported as not trusted, but mail is being delivered. Does it matter?
Opportunistic STARTTLS (RFC 3207) encrypts without verifying the certificate, so ordinary delivery continues. Senders that do verify - MTA-STS in enforce mode, or DANE - will refuse to deliver to that server. Use a certificate from a public CA that covers the MX hostname, which is the name senders check.
Read the full MX Lookup and SMTP Test guide