Updated: 28 September 2026 · Applies to: Self-managed dedicated servers
Mail servers talk to each other on TCP port 25. On Ucartz servers the SMTP ports are enabled and nothing is blocked by default, so outgoing port 25 should work from the start. Still, test it before you install anything: it takes a minute, and it shows quickly if a firewall on your own server, a routing problem on an extra address or the remote server is the cause. You can also test from a specific IP address of your server.
1. Test the connection
From your server, connect to the public mail server of a large provider (any well-known mail server works; this one is only an example):
nc -vz -w 10 gmail-smtp-in.l.google.com 25
A result like Connection ... succeeded means outgoing port 25 works. If it hangs and times out, something between your server and the remote server filters the port.
2. Look at the greeting
openssl s_client -starttls smtp -connect gmail-smtp-in.l.google.com:25 -crlf
You should see a certificate and the server's greeting beginning with 250. Type QUIT and press Enter to leave. If the greeting arrives, mail can be delivered from this address.
3. Test from each IP address
for ip in 203.0.113.10 203.0.113.11 203.0.113.12; do echo -n "$ip: " nc -s $ip -vz -w 10 gmail-smtp-in.l.google.com 25 2>&1 | tail -1 done
Every address that will send mail must be able to connect. If the main address works and an extra one does not, the extra address is not routed for outgoing traffic: see How to test that every additional IP address works on your server?.
4. Test the other mail ports
- Port 587 (submission) and 465 (SMTPS) are used by applications that send through a mail server with a login. Test with
nc -vz -w 10 HOSTNAME 587against the mail server you use. - Incoming port 25 on your own server matters only if you receive mail. Test from another machine:
nc -vz -w 10 YOUR-SERVER-IP 25.
If the connection times out
- Check your own firewall for outgoing rules:
sudo ufw status verboseorsudo nft list ruleset. - Test from a second address or a second network to see if it is address-specific.
- Ucartz does not block port 25 by default, so a time-out is usually caused by your own firewall, by the routing of an extra address (How to test that every additional IP address works on your server?) or by the remote server. If you still cannot find the cause, open a support ticket with the output of the tests and the address you used.
If the connection works but the greeting is refused
Some servers reject connections from addresses without reverse DNS, or from addresses on blocklists. Set the reverse DNS (How to set reverse DNS (PTR) for many IP addresses and check forward-confirmed rDNS?) and check the address (How to check whether a new IP address is on a blocklist before you use it?).
Frequently asked questions
Is it a problem to connect to Google's mail server for a test?
No. A short connection to check reachability is normal. Do not run tests in a loop for a long time.
Next step?
Install the mail server: How to install and configure Postfix for sending on Ubuntu?.
Need a dedicated server, more IP addresses, or a hand with the setup?
- Unmanaged dedicated servers: full root access and IPv4 subnets from /29 up to /24, ordered with the server or added later.
- Managed dedicated servers: our team looks after the operating system, updates, security and monitoring.
- Dedicated server locations: choose the country and data centre when you order.
Prefer a hand with the setup? Our engineers can do it for you: Hire an Expert, or use our on-demand server management.
