Email & SMTP

SMTP Server Configuration Check

A focused check of your SMTP server's configuration for common misconfigurations and security gaps.

The Problem

You're not sure if your SMTP server (Postfix, Exim, hMailServer, etc.) is configured sensibly, securely, or if it's quietly acting as an open relay that spammers have found.

About this problem

A self-managed SMTP server (Postfix, Exim, hMailServer) doesn't come securely configured by default, and issues like open relay vulnerabilities or weak encryption settings often go unnoticed for a long time, since the server keeps working normally from the owner's perspective even while quietly being misused or exposed.

This gets requested as a precautionary check, after noticing unusual server load or outgoing mail activity, or simply because the server was set up a long time ago and never properly reviewed.

What's Included

What's NOT Included

How It Works

  1. Test the server directly for open relay vulnerabilities — whether it accepts and forwards mail from unauthenticated senders.
  2. Review authentication requirements and TLS/encryption settings for weaknesses.
  3. Check port configuration and firewall rules specific to mail services.
  4. Compile findings into a written summary with clear priority levels.
  5. Flag anything suggesting the server may already be compromised or misused.

In practice: you buy the service, send over whatever access or details the job needs, I investigate and do the work, and you confirm it's resolved before we call it done.

Frequently Asked Questions

How do I know if my SMTP server is an open relay?
The only reliable way is to actually test it by attempting to relay mail through it without authentication from an external vantage point, rather than assuming based on the configuration file alone.
What's a sign my mail server might already be misused by spammers?
Unusually high outbound mail volume you didn't initiate, your IP showing up on blacklists, or unexplained server load are common warning signs worth investigating.
Is hMailServer as secure as Postfix or Exim?
All three can be configured securely or insecurely — the specific settings matter far more than which software is used, which is why this check reviews actual configuration rather than assuming based on the platform.
Does this check fix any problems it finds?
No, it's diagnostic — findings come with priority levels, and fixes are quoted and scheduled separately once the scope is known.
How often should an SMTP server be security-checked?
At least annually for a server that doesn't change often, or sooner if anything about its behaviour seems different from normal.
Can a misconfigured SMTP server get my domain blacklisted?
Yes — an open relay is a classic way for spammers to abuse a server without authorisation, which can quickly get the server's IP blacklisted as a result.
Please note: the price shown applies to a standard case matching the description above. Every situation is different, and if your request falls outside the normal scope of this service, I will explain this before doing any additional chargeable work. I will never silently turn a small job into an expensive project.
Running into an issue with a service you've already bought, or unsure which one fits your problem? Message me directly on WhatsApp — no ticket system, no bot.