[{"data":1,"prerenderedAt":198},["ShallowReactive",2],{"seo-verification":3,"blog-email-deliverability-on-vps-port-25-cold-ip-and-ptr-en":6},{"google":4,"bing":5},"EycwPY2XMyTkVzas3n1ygeNJFGAH513qrMjfDljzsMQ","",{"key":7,"data":8},"blog-email-deliverability-on-vps-port-25-cold-ip-and-ptr-en",{"id":9,"slug":10,"slugs":11,"title":15,"excerpt":16,"readTime":17,"views":18,"isPinned":19,"publishedAt":20,"category":21,"categories":26,"featuredImage":28,"bgImage":29,"posterImage":30,"relatedSolution":28,"intro":31,"sections":32,"ctaTitle":147,"ctaBody":148,"ctaButton":149,"ctaUrl":150,"relatedPosts":151},331,"email-deliverability-on-vps-port-25-cold-ip-and-ptr",{"fr":12,"en":10,"ar":13,"es":14},"email-deliverabilite-vps-port-25-dkim-ptr","تسليم-البريد-الإلكتروني-على-vps-المنفذ-25-وـ-ptr","entregabilidad-de-email-en-vps-puerto-25-ip-fria-y-ptr","Email deliverability on VPS: port 25, cold IP and PTR","Port 25 blocked by the provider, fresh IP flagged as spam, missing PTR: the three structural blockers to resolve before your first send from a VPS.",9,1,false,"2026-09-05T00:00:00+00:00",{"id":22,"name":23,"slug":24,"color":25,"icon":24},11,"Business Email","emails","bg-cyan-500\u002F10 text-cyan-400",[27],{"id":22,"name":23,"slug":24,"color":25,"icon":24},null,"\u002Fblog\u002Fcovers\u002Fbg.svg","\u002Fblog\u002Fcovers\u002Femail-deliverabilite-vps-port-25-dkim-ptr-poster.svg","You have just installed Mailcow or Stalwart on your VPS. The first emails bounce with a 550 error or disappear into the spam folder without any error message. Installation guides do not explain why — because the problem does not come from the mail server configuration, but from the network layer underneath. Three structural blockers arise before the first SMTP handshake: outbound port 25 closed by the provider, a newly allocated IP already flagged as cold or suspicious, and a missing or mismatched PTR record. This guide addresses them in the order they block, with diagnostic commands and real procedures per provider.",[33,37,40,47,63,67,70,78,93,96,102,115,135,144],{"type":34,"title":35,"body":36},"h2","Why these three blockers come before everything else","SPF, DKIM and DMARC are DNS records you control entirely. The three blockers covered here depend partly on your hosting provider and on the reputation of the IP you were assigned. Configuring DKIM is pointless if outbound port 25 is filtered at the hypervisor level: your server will attempt to deliver the message, will never reach the recipient's MX, and will log a connection error.\n\nThe resolution order is therefore: port 25 → IP reputation → PTR. Only once these three points are validated does authentication checking (SPF, DKIM, DMARC) make sense.",{"type":34,"title":38,"body":39},"Blocker 1: outbound port 25 is closed by default","Most hosting providers block outbound port 25 on new accounts. This is not an oversight: it is a deliberate, documented, and liftable anti-spam measure.",{"type":41,"title":42,"items":43},"ul","Quick diagnosis from your VPS",[44,45,46],"Test outbound connectivity to an external MX: `nc -zv gmail-smtp-in.l.google.com 25` — \"Connection refused\" or a timeout indicates upstream filtering from your server","Also check with `telnet smtp.example.com 25`: if the connection opens and you see the `220` banner, the port is open; otherwise, the block comes from the provider or an intermediate firewall","Distinguish a network block from an application refusal: an immediate `ECONNREFUSED` comes from the provider firewall, a timeout from a local iptables rule or upstream BGP filtering",{"type":48,"title":49,"steps":50},"steps","Unblocking procedure per provider",[51,54,57,60],{"title":52,"body":53},"Hetzner","Hetzner blocks port 25 on all new projects. Unblocking is done via a support ticket from the Hetzner Cloud console (\"Support\" section). Observed conditions: verified account with an active credit card, legitimate use described (personal or business mail server, owned domain). The delay is typically 24 to 72 hours. Include in the ticket the IPv4 address of your instance, the domain you plan to use, and the estimated sending volume. Hetzner Robot (dedicated servers) follows the same procedure, opened from the \"Support\" tab of the Robot interface.",{"title":55,"body":56},"Scaleway","Scaleway offers an SMTP unblocking request form in the console, under \"Security groups\" or from the organization settings (depending on the interface version). You need to describe the use case and the sender domain. Processing is manual on Scaleway's side; the observed delay is one to three business days. Once validated, the unblocking applies at the security group level for your project — also verify that port 25 is not blocked in your own security group.",{"title":58,"body":59},"OVH \u002F OVHcloud","On OVH Public Cloud (Nova instances), outbound port 25 may be filtered depending on the project type. The process goes through the OVH customer area, in the \"Bare Metal Cloud\" or \"Public Cloud\" section depending on your product. Look for the \"Outbound anti-spam\" option or open a ticket from the customer area specifying the instance type and intended use. On classic OVH VPS (SSD \u002F Comfort \u002F Elite range), port 25 is open by default but may be blocked if your account has triggered alerts.",{"title":61,"body":62},"Other providers","The principle is the same for most providers: unblocking is possible, conditional, and documented in their support base. Search for \"SMTP port 25 unblock\" or \"outbound email policy\" in their documentation. If the procedure is not public, a support ticket is sufficient — always specify the IP, domain and estimated volume.",{"type":64,"title":65,"body":66},"tip","Alternative ports: 587 and 465 do not replace port 25","Ports 587 (submission) and 465 (SMTPS) are used for email submission by mail clients to your own server. Server-to-server delivery (MTA-to-MTA) happens on port 25. If your VPS cannot open an outbound connection on port 25, you will not be able to deliver directly to recipient MX servers, regardless of how your other ports are configured.",{"type":34,"title":68,"body":69},"Blocker 2: the reputation of a newly allocated IP","An IPv4 address allocated to your VPS is not blank. It may have belonged to a previous tenant who used it to send spam. Anti-spam filters at major mail providers (Gmail, Outlook, Yahoo) maintain blacklists of IP addresses — some are maintained by third-party organizations (Spamhaus, SORBS, Barracuda), others are proprietary.\n\nA typical IP-related rejection looks like: `550 5.7.1 Service unavailable; Client host [x.x.x.x] blocked using Spamhaus`. The mention of the blacklist organization tells you where to request removal.",{"type":41,"title":71,"items":72},"Check your IP reputation before the first send",[73,74,75,76,77],"Check multiple blacklist databases in one query via \u003Ca href=\"https:\u002F\u002Fmxtoolbox.com\u002Fblacklists.aspx\">MXToolbox Blacklist Check\u003C\u002Fa>: enter your IPv4 address and run the analysis","For a command-line check, `curl -s \"https:\u002F\u002Fapi.abuseipdb.com\u002Fapi\u002Fv2\u002Fcheck?ipAddress=\u003Cyour-ip>&maxAgeInDays=90\" -H \"Key: \u003Cyour-key>\"` returns a confidence score and report history if you have an AbuseIPDB API key","If your IP is listed at Spamhaus (SBL, XBL, PBL), \u003Ca href=\"https:\u002F\u002Fwww.spamhaus.org\u002Flookup\u002F\">the removal procedure\u003C\u002Fa> is documented on their site; the delay ranges from a few hours to 48 h","If the IP is in the Barracuda Reputation Block List, removal is requested via \u003Ca href=\"https:\u002F\u002Fwww.barracudacentral.org\u002Frbl\u002Fremoval-request\">their online form\u003C\u002Fa>","If no blacklist flags your IP but emails still land in spam, the problem comes from a missing PTR (blocker 3) or DNS authentication (SPF\u002FDKIM\u002FDMARC)",{"type":48,"title":79,"steps":80},"Progressive warm-up of a cold IP",[81,84,87,90],{"title":82,"body":83},"Start with minimal volume","In the first few days, limit sends to a few dozen messages daily to known and engaged recipients (no purchased lists or mass sends). Filters will learn that your IP produces legitimate traffic.",{"title":85,"body":86},"Increase volume gradually","Roughly double the volume each week: 50 → 100 → 200 → 500 → 1,000 messages per day. This indicative schedule depends on your domain, your open rate and the absence of spam reports. A cold IP that immediately sends 10,000 messages will be filtered or blocked before its messages are even read.",{"title":88,"body":89},"Monitor deliverability metrics","Review DMARC reports (the `rua` field in your DMARC record) to detect rejections and blacklist returns. A hard bounce rate above 2% or a spam complaint rate above 0.1% should prompt you to pause and diagnose before resuming.",{"title":91,"body":92},"Use a score tool to validate the setup","\u003Ca href=\"https:\u002F\u002Fwww.mail-tester.com\">mail-tester.com\u003C\u002Fa> gives you a score out of 10 by analyzing headers, authentication, content and the sender IP reputation. Send a test message to the provided address and review the detailed report. Aim for 9\u002F10 or above before launching your first production sends.",{"type":34,"title":94,"body":95},"Blocker 3: the missing or mismatched PTR (rDNS)","The PTR (Pointer record, also called reverse DNS or rDNS) associates your IP address with a domain name. Unlike A or MX records that you create in your DNS manager, the PTR is configured on the provider side — they control the reverse DNS zone for their IP address block.\n\nReceiving servers check the PTR at every incoming connection: if the IP address the message originates from does not resolve to a name, or if that name does not match the hostname announced in the `HELO`\u002F`EHLO` of your MTA, the message is often rejected or heavily penalized.",{"type":41,"title":97,"items":98},"PTR diagnosis in two commands",[99,100,101],"Check the current PTR for your IP: `dig -x \u003Cyour-ip> +short` — if the command returns nothing, the PTR is not configured","Check consistency with your mail server hostname: the result of `dig -x` should match the name your MTA announces in the `EHLO`, which you can find in the Postfix configuration (`myhostname`), Stalwart or Mailcow","Do the reverse test: `dig \u003Cname-returned-by-dig-x> +short` should return your IP — this is forward-confirmed rDNS (FCrDNS) validation, which some filters require",{"type":48,"title":103,"steps":104},"Configure the PTR from your provider panel",[105,108,111,113],{"title":106,"body":107},"Hetzner Cloud","In the Hetzner Cloud console, go to your server, then to the \"Networking\" tab. Click on the IPv4 address, then on \"Edit reverse DNS\". Enter the fully qualified domain name (FQDN) that your MTA announces in the EHLO — for example `mail.yourdomain.com`. The change propagates within a few minutes.",{"title":109,"body":110},"Hetzner Robot (dedicated servers)","In the Hetzner Robot interface, go to the \"Servers\" section, choose your server, then the \"IPs\" tab. Click on the relevant IPv4 address and fill in the \"PTR record\" field with your FQDN.",{"title":55,"body":112},"In the Scaleway console, go to your instance, then to \"IP addresses\". Next to your IPv4 address, click the context menu and choose \"Edit reverse DNS\". Enter the FQDN of your mail server.",{"title":58,"body":114},"In the OVH customer area, go to \"Bare Metal Cloud\" or \"Public Cloud\" depending on your product, then to the \"IP\" section. Locate your address and use the \"Edit reverse\" option. The expected format is a FQDN ending with a period in some interface versions — check the documentation for your customer area version.",{"type":116,"title":117,"headers":118,"rows":122},"comparison","Summary of the three blockers",[119,120,121],"Blocker","Observed symptom","Resolution",[123,127,131],[124,125,126],"Port 25 closed","Connection refused or timeout to remote MX, connection error in MTA logs","Provider support ticket, 24-72 h delay",[128,129,130],"Cold or blacklisted IP","550 rejection mentioning a blacklist, delivery to spam from the first hours","Blacklist removal, progressive warm-up",[132,133,134],"Missing or mismatched PTR","550 rejection mentioning reverse DNS, score penalty in anti-spam filters","Configuration from the provider panel",{"type":41,"title":136,"items":137},"Validate everything before going to production",[138,139,140,141,142,143],"`nc -zv \u003Ctarget-mx> 25` returns `succeeded` — outbound port 25 is open","`dig -x \u003Cyour-ip> +short` returns the FQDN of your mail server — PTR is configured","That FQDN resolves to your IP via `dig \u003Cfqdn> +short` — FCrDNS is valid","Your IP does not appear in any major blacklist checked via MXToolbox","A test message sent to mail-tester.com scores 9\u002F10 or above","SPF, DKIM and DMARC records are in place and validated — see \u003Ca href=\"\u002Fblog\u002Fspf-dkim-dmarc-delivrabilite-emails-pro\">SPF, DKIM, DMARC: crossing the 5,000 email threshold\u003C\u002Fa> for the detailed configuration",{"type":64,"title":145,"body":146},"With a dedicated IPv4, you control the full chain","On shared hosting, you share the sending IP address with other customers — and their reputation affects yours without you being able to act on it. On a VPS with a dedicated IPv4, the PTR, the reputation and the email stack configuration are entirely yours. That is the technical condition that makes this guide possible.","A VPS with a dedicated IPv4 for your sends","Port 25 unlockable, PTR configurable, non-shared dedicated IP: the three technical conditions that make a reliable self-hosted mail server possible. Our VPS plans start at 99 DH\u002Fmonth and include full root access.","View VPS plans","\u002Fvps-cloud",[152,168,183],{"id":153,"slug":154,"slugs":155,"title":159,"excerpt":160,"readTime":161,"views":162,"isPinned":19,"publishedAt":163,"category":164,"categories":165,"featuredImage":28,"bgImage":29,"posterImage":167,"relatedSolution":28},199,"spf-dkim-dmarc-passing-the-5000-email-threshold",{"fr":156,"en":154,"ar":157,"es":158},"spf-dkim-dmarc-delivrabilite-emails-pro","spf-وdkim-وdmarc-تجاوز-عتبة-5000-رسالة","spf-dkim-dmarc-superar-el-umbral-de-5000-correos","SPF, DKIM, DMARC: passing the 5,000-email threshold","Gmail and Outlook reject senders without aligned SPF, DKIM and DMARC with an SMTP 550 error. Here is how to configure all three records.",4,0,"2026-08-01T00:00:00+00:00",{"id":22,"name":23,"slug":24,"color":25,"icon":24},[166],{"id":22,"name":23,"slug":24,"color":25,"icon":24},"\u002Fblog\u002Fcovers\u002Fspf-dkim-dmarc-delivrabilite-emails-pro-poster.svg",{"id":169,"slug":170,"slugs":171,"title":175,"excerpt":176,"readTime":177,"views":18,"isPinned":19,"publishedAt":178,"category":179,"categories":180,"featuredImage":28,"bgImage":29,"posterImage":182,"relatedSolution":28},238,"hosting-your-own-email-server-on-a-vps-with-mailcow",{"fr":172,"en":170,"ar":173,"es":174},"heberger-serveur-email-vps-mailcow","استضافة-خادم-البريد-الإلكتروني-على-vps-باستخدام-mailcow","alojar-servidor-correo-vps-mailcow","Hosting Your Own Email Server on a VPS with Mailcow","Deploy Mailcow on a Linux VPS to run your own sovereign email server: installation, deliverability and migration from Google Workspace.",13,"2026-08-08T00:00:00+00:00",{"id":22,"name":23,"slug":24,"color":25,"icon":24},[181],{"id":22,"name":23,"slug":24,"color":25,"icon":24},"\u002Fblog\u002Fcovers\u002Fheberger-serveur-email-vps-mailcow-poster.svg",{"id":184,"slug":185,"slugs":186,"title":190,"excerpt":191,"readTime":192,"views":162,"isPinned":19,"publishedAt":193,"category":194,"categories":195,"featuredImage":28,"bgImage":29,"posterImage":197,"relatedSolution":28},280,"postfix-smtp-relay-on-vps-client-transactional-emails",{"fr":187,"en":185,"ar":188,"es":189},"smtp-relay-vps-emails-transactionnels-clients","إعداد-postfix-smtp-relay-على-vps-لبريد-المواقع","relay-smtp-postfix-en-vps-emails-transaccionales","Postfix SMTP Relay on VPS: Client Transactional Emails","Set up Postfix as an SMTP relay on a ServOrbit VPS: dedicated IPv4, SPF, DKIM and DMARC aligned for your entire cPanel client portfolio in under an hour.",8,"2026-08-18T00:00:00+00:00",{"id":22,"name":23,"slug":24,"color":25,"icon":24},[196],{"id":22,"name":23,"slug":24,"color":25,"icon":24},"\u002Fblog\u002Fcovers\u002Fsmtp-relay-vps-emails-transactionnels-clients-poster.svg",1789046151864]