Developer & Website SMTP

How to Send Transactional Website Email Without Running Postfix

The VPS stays a website. Copy dashboard SMTP. Close port 25. Prove both directions.

MailerZ editorial · Secuno LLC16 min read

Sending website email without Postfix means the form or app talks authenticated SMTP to a hop you already pay for, not a listener on your VPS. MailerZ paid send-as uses dashboard host, port, and user. From must be a mapped alias. Replies need exclusive inbound MX. Free has no send-as. Port 25 on a public VPS is how open relays start. Caps live on pricing. This is transactional mail, not a list blast.

Website form uses paid SMTP from the dashboard; do not run Postfix on the VPS
Copy dashboard SMTP. Do not listen on 25. From must be mapped.

Quick answer for send website email without postfix

Upgrade off Free. Copy SMTP from the dashboard into env. Send as hello@ or notify@ that exists on the map. Point MX at MailerZ only so replies return. Product path: send and reply, docs, features. Transport is IETF RFC 5321 — Simple Mail Transfer Protocol. SPF is IETF RFC 7208 — Sender Policy Framework (SPF). DKIM is IETF RFC 6376 — DomainKeys Identified Mail (DKIM). Competitor SMTP docs: ImprovMX SMTP — quote live, do not copy ports from memory.

Confirm MailerZ pricing. Solo is $40 per year. Starter is $8 or $80. Business is $19 or $190. Agency is $39 or $390. Hourly and monthly send caps apply. 550 5.7.1 is authorization, not leftover MX. No inbox SLA. Not an open relay. Not SOC 2.

Helpful content is a working form, not a Postfix novel: people-first pages. CAN-SPAM still applies if you mail lists—see US Federal Trade Commission — CAN-SPAM compliance guide. This hop is not a campaign sender.

The user problem and the decision criteria

Tutorials still say “install Postfix on Ubuntu.” That tutorial assumes you want a mail server. A contact form wants a client. Those are different jobs. A VPS that accepts unauthenticated mail is an open relay. A VPS that only submits to MailerZ is a website.

Postfix versus paid SMTP
QuestionIf yesIf no
Do you need a local queue you operate?You are shopping for a mail server.Use authenticated SMTP.
Is From a mapped alias?Paid send-as can work.550. Create the alias first.
Is MX exclusive MailerZ?Replies can return.Leftover MX steals replies.
Is this a newsletter?Use a list vendor. Quote them live.Transactional caps may fit.
Port 25 open on the VPS?Close it. You are the listener.Good. Submit outbound only.

Technical mail flow

The site authenticates to MailerZ SMTP and offers MAIL FROM as the mapped alias. MailerZ accepts or returns 550. Recipients resolve their own MX. Replies come back to your MX. If leftovers remain, some replies never reach Gmail. History shows hops we accepted. Empty history on send is a client or auth problem, not leftover inbound MX—unless you mixed tickets.

Send via paid SMTP and receive replies on exclusive MX
Two directions. One owner inbound. Paid outbound. Rate-limit the form.

Envelope SRS applies to forwarded inbound, not to your authenticated send. Header From on send should be the alias you authorized. Do not rewrite visitor From as if they sent the mail. That breaks DMARC for their domain and can look like spoofing.

Microsoft device-send guidance is a different product; see Microsoft Learn — Send email from a device or app using Microsoft 365 if the destination is M365. Do not copy their ports onto MailerZ.

Step-by-step setup and decision path

  1. Map the From alias and exclusive MX

    hello@ or notify@ into a staffed Gmail. Delete leftover MX. Probe inbound first.

  2. Upgrade off Free

    Copy SMTP host, port, username, and password from the dashboard. Do not invent 587 vs 25 from a blog.

  3. Put secrets in env

    Gitignore .env. Rotate on leak. See the env article if you already have one.

  4. Send as the mapped alias only

    Do not set From to the visitor. Put the visitor in Reply-To if you must, and understand spam filters.

  5. Rate-limit and cap

    One submit per minute per IP is a start. Watch monthly outgoing on pricing.

  6. Prove both directions

    Unique subject to a third mailbox. Then reply to hello@. History 250 both ways.

Prove SMTP with a third mailbox; copy dashboard ports; 550 is authorization
Third mailbox. Dashboard values. Do not loop a 550.

Failure modes and proof

Website SMTP failure, likely cause, next action
What you seeLikely causeProof
550 5.7.1Free, bad From, or bad userPlan and dashboard From
Timeout on 25You invented a port or the VPS blocks 25Dashboard port; do not run a listener
Send works, replies vanishLeftover MXTwo resolvers
Visitor From, DMARC failYou spoofed the visitorSend as your alias
Spam from the formNo rate limitCap and CAPTCHA
Cron retries a 550You looped a permanent failStop. Fix auth.

Proof is dashboard values, a unique outbound 250, inbound reply 250, and a closed port 25 on the VPS. Agencies: per-site credentials. Do not share one SMTP user across clients.

MailerZ workflow and product boundary

MailerZ is inbound MX plus authenticated SMTP. Envelope SRS on forward. Header From never rewritten on inbound. Outbound From must be authorized. Not IMAP. Not Postfix. Not an open relay. Unhosted SMTP is 550 / 550 5.7.1.

Free: one domain, three aliases, 14-day store, send-as disabled, SMTP and API disabled. Solo $40 per year. Starter $8 or $80. Business $19 or $190. Agency $39 or $390. Confirm pricing. Caps are not an inbox SLA. No SOC 2.

Features describe routing and send. They do not install a daemon on your VPS. Paid plans do not buy a list platform.

Cost, alternatives, and trade-offs

Spend versus what you operate
ChoiceWhat you getWhat you give up
Paid MailerZ SMTPA client, not a serverLocal queue you debug at 3 a.m.
Postfix on the VPSA mail server. Quote your timeSleep and a closed port 25
Transactional API vendorTheir SDK. Quote liveMailerZ From if you split identity
php mail() via local sendmailA surprise open pathAuthentication
Workspace SMTP for the formA suite. Quote Google liveThe hop you already use for aliases

Time is a line item. Dashboard SMTP costs less than a week hardening Postfix. Leftover MX costs more than Solo. A Free-plan send-as argument still costs more than the upgrade.

What Postfix would force you to own

A local MTA means queue, TLS, reputation, blocklists, and abuse of your IP. Cloud VPS IPs are often pre-warmed as spam. That is not “simple.” Authenticated submit to MailerZ keeps the VPS a website.

If you already run Postfix for other reasons, still do not accept the internet on 25 for the contact form. Submit outbound through MailerZ or you have two send paths and two reputations.

Open relays are a later article. The short version: unauthenticated inbound SMTP on a public host will be found. Verified sending is the opposite design.

IPv6 on the website is not IPv6 on MX. Do not open 25 because AAAA exists. Close 25. Use the dashboard port for submit.

Forms, rate limits, and From

The form sends as hello@yourdomain, body includes the visitor message, Reply-To may be the visitor. Many filters distrust Reply-To. Prefer a ticket id and staff reply from hello@.

CAPTCHA and rate limits are your application. MailerZ caps do not replace them. A bot that hits the monthly outgoing limit pauses send. That is a policy stop, not leftover MX.

WordPress plugins want host, port, user, pass, From. Paste dashboard values. Do not paste Gmail app passwords into a MailerZ field. Two-direction probe after each plugin update.

Attachments from visitors are malware risk in Gmail, not a MailerZ feature. Size limits are yours. Do not turn the form into a file drop.

Multiple sites on Agency still need per-site From aliases and, preferably, per-site SMTP users. Shared credentials across clients is the next article’s failure mode.

Credentials in env, not in git

SMTP passwords are not code. .env locally, platform secrets in production. Rotate when a contractor leaves or a repo leaks. History of a leaked password is not an inbox SLA.

Do not log the password. Do not log full AUTH lines. Log the 250 or 550 and a request id.

Night deploys that revert .env to empty will 550. That is not leftover MX. Fix the secret, then one probe, not a cron storm.

SPF, DKIM, and DMARC must match the sending hop. Two SPF TXT records permerror. Copy dashboard values. IETF RFC 7489 — Domain-based Message Authentication, Reporting, and Conformance (DMARC) is policy, not a form plugin.

Registrar republish of email MX steals replies, not necessarily sends. Re-query after website DNS saves. Exclusive inbound still matters for the loop.

Legal hold of form mail lives in Gmail and your app logs. MailerZ store windows help hops we accepted. They are not a SIEM.

Two-factor on the destination Gmail. Open a held unknown if a typo From was used. Audit row. Not SOC 2.

If a second operator needs the order, send this page plus leftover MX troubleshooting. Map alias. Exclusive MX. Paid SMTP from dashboard. Rate-limit. Prove both directions. That order prevents a Postfix weekend.

Paid plans do not install Postfix. They authorize send-as and raise caps. They do not buy a campaign sender or an open port 25.

The artifacts that close send website email without postfix are dashboard SMTP in env, a unique outbound 250, an inbound reply 250, and a VPS that does not listen on 25. Everything else is a mail server you did not mean to buy.

The VPS does not need port 25

Transactional website email without Postfix means the form or app AUTHs to paid MailerZ SMTP using the host, port, and user from the dashboard, and sends as a mapped alias. The VPS does not listen on 25. It does not become an open relay. Unhosted or unauthorized From is 550 / 550 5.7.1. Free has no send-as. If you are on Free, the form cannot use MailerZ as From. Pay Solo or higher, or keep the form on a dedicated transactional vendor.

Caps: 50/100/200/400/800 outgoing per month and 5/10/15/25 per hour. A contact form that emails you once per submit is in class if humans are rare. A password-reset blast or a newsletter cron is not. Buy a bulk or transactional ESP for that. MailerZ is human-scale operational sending. Do not cron retries into a 550 loop.

Inbound is a separate hop. Replies to hello@ need exclusive MailerZ MX, a named alias, and Gmail or Outlook as the store. Publishing SMTP without exclusive MX means replies wander into leftover Google. Two resolvers. Delete leftovers.

One SPF TXT with the dashboard include. Two v=spf1 is permerror. DKIM and DMARC as shown. Do not copy last year’s port list. STARTTLS versus implicit TLS are different conversations. Wrong host is a timeout or 550, not an inbox SLA.

Secrets live in env, not in git, not in the ticket. Rotate if the VPS was copied. Revoke the identity if the form is retired. Dashboard values only.

Header From is the approved identity. We do not rewrite inbound Header From. Outbound From must be a mapped alias. Random envelope tricks do not authorize a new From.

Self-send from the form to your own Gmail can lie. Submit to a third-party mailbox. Confirm history 250 and Header From. Then reply to that message to prove inbound.

Postfix on the same VPS “as backup” is how you get an open relay and a second From path. Pick one sender. MailerZ or a proper ESP. Not both, and not port 25 to the world.

Rate-limit the form. A scraped form will burn Solo’s 5/hour and look like an outage. 550 at the cap is the product. Back off.

WordPress, Laravel, and Next.js all AUTH the same way: host, port, user, secret, From identity. Plugins that default to php mail() or localhost:25 are the Postfix temptation. Change the plugin to SMTP. Do not invent a local MTA to “just get it working.”

Failure classes that are not Postfix bugs

550 unauthorized: From not mapped or Free plan. Map the alias. Pay. Do not open port 25.

Empty inbound after someone replies: leftover MX. Two resolvers. Not an SMTP host typo.

Permerror: two SPF records. Merge. See the SPF duplicate article if you need that worksheet.

Destination 5xx after 250: Gmail refused the notification. Copy the line. Do not add Postfix.

Hourly 550: cap. Starter is 10/hour. Slow the form or buy a real ESP.

Agencies: one SMTP identity per client. Shared credentials across sites is how one breach sends as everyone. Agency 25/hour is still not a license to share.

No inbox SLA for form mail. No SOC 2 claim. /security. /pricing.

Start free to prove inbound aliases. Pay before the form sends as the domain. Sign in to copy dashboard SMTP. Do not listen on 25 while you wait.

Envelope SRS applies to inbound forwards, not to your AUTH session. Do not “set SRS” in Postfix to imitate us. You are not running our hop.

If you truly need a local MTA, you accepted operations we do not sell: queues, reputation, abuse desk. This page is how to avoid that job.

Paid SMTP is the path; port 25 is the nostalgia

Postfix on a VPS feels like control until the first blocklist, the first ISP that ignores port 25, and the first password-reset that lands in spam because the box has no PTR you understand. Transactional website email is a submission job: your app authenticates to a provider over submission, the provider signs, and you keep one SPF. MailerZ paid send-as can be that submission when you send as the domain the hop already receives. Free cannot send. Do not install Postfix to paper over a Free plan.

Port 25 outbound from a cloud VM is often filtered. That is not a MailerZ policy. That is how clouds stop open relays. If your “SMTP” tutorial starts with firewall allow 25, you are reading a 2012 guide. Use authenticated submission on the port the provider documents. Treat a 550 from MailerZ as plan or identity, not as a hint to fall back to Postfix. Fallback to Postfix is how you create a second sender the SPF record forgot.

Bulk is out of scope. This article is password resets, invoices, and “you signed up” mail. A newsletter tool is a different hop and a different include. Putting campaign mail through the same Postfix that also forwards inbound is how you train filters to hate the brand. If you need campaigns, buy a campaign product. If you need send-as from a person, use paid MailerZ SMTP. If you need both, two includes in one v=spf1, still one record.

The app should not own a mailbox. The app should own credentials, a from identity that exists as a paid alias or send-as identity, and a bounce handler. IMAP is not the transactional path. MailerZ is not IMAP. Do not poll Vault for order confirmations. Send, log the provider id, and handle webhooks or DSN if the provider offers them. Inventing a mailbox for the app is how you get a forgotten Postfix queue on a Friday.

Identity comes first. The Header From you send must be a domain you control and a local-part you are allowed to send. Creating the alias before the first send avoids HOLD confusion on inbound replies. Replies to transactional mail are inbound. They need MX and a named alias if humans must read them. noreply@ with no inbound plan is a choice. support@ with leftover MX is an accident.

Secrets live in the environment, not in the repo. Rotate the SMTP password when a contractor leaves. Do not share the same credential with a staging box that sends to real customers. Staging should send to a sink or a plus-address you watch. A staging Postfix that can reach the internet is an open invitation. Paid SMTP with a separate credential is cheaper than an incident.

Timeouts and retries belong in the app. Do not let the web request block on the provider for thirty seconds. Queue the send. Retry with backoff. Idempotency keys stop double password resets when the worker runs twice. Postfix queues hide this until the disk fills. A managed submission queue you can see in logs is an operational improvement, not a religion.

Proof of send is a stranger mailbox, not the founder’s Gmail that already trusts the domain. Send the reset template to a Proton address. Check authentication headers. If SPF is permerror, you have two v=spf1 or a broken include. Fix the record. Do not add Postfix “to be sure.” Sure is one policy and one hop.

Leftover MX does not block outbound, which is why founders ship sending first. Customers then reply to hello@ and the reply dies on leftover Google. Inbound exclusive MX is still a prerequisite if humans must read replies. The transactional checklist is: domain verified, alias exists, paid send enabled, one SPF, DKIM for this hop, stranger proof, then inbound MX if replies matter. Reverse only if you enjoy angry tickets.

Plans: Free has no send-as. Solo and up add sending when you enable it. Caps live on /pricing. No inbox SLA. No SOC 2 claimed here. Envelope SRS is for inbound forward, not a reason to run your own MTA. Start free to receive. Upgrade to send. Sign in when the identity already exists.

If you already have Postfix, freeze inbound relay first. Point MX at MailerZ exclusively. Move transactional submission to paid SMTP. Then turn off the box’s outbound. Leaving Postfix “as backup” is leftover MX’s cousin: leftover MTA. Backup is a screenshot of the old config, not a process that still listens.

App checklist that keeps Postfix off the box

Environment has the submission host, port, user, and password. From identity exists as a paid send-as identity. One v=spf1 includes that hop only. DKIM selector matches what the dashboard issued. Worker queue exists. Staging credential cannot reach production customers. Stranger mailbox received a reset last week. Inbound MX is exclusive if humans read replies. If any box is unchecked, you are not ready to delete Postfix, and you are not ready to keep it either. You are ready to finish the list.

When a 550 appears, read the text. Plan and identity are hop answers. Blocklist on a VPS is a Postfix answer. Do not cross the wires. Free users who see they cannot send should upgrade or stop promising founder@ from the app. They should not apt-get install postfix. Start free to receive. Upgrade to send. Sign in when the identity is already named.

FAQ

What is the safest way to handle send website email without postfix?

Use paid MailerZ SMTP with the host, port, and user from the dashboard. Send as a mapped alias. Exclusive inbound MX so replies land. Rate-limit the form. Do not listen on port 25 on the VPS. Free has no send-as. Unhosted From is 550 5.7.1.

Does this require a new mailbox?

No. Gmail or Outlook can stay the store for replies. MailerZ is not IMAP. Postfix on a VPS is a mail server you would operate. Skip it unless you want that job.

Will it work with Gmail or Outlook?

Recipients can be anyone. Replies to hello@ need exclusive MX and a mapped alias into Gmail or Outlook. Self-send is a bad gate. Free cannot send as the domain.

What DNS records are involved?

Inbound: exclusive MailerZ MX, verification TXT, leftovers deleted. Outbound: SPF, DKIM, and DMARC as the dashboard shows. Two SPF records permerror. See RFC 5321, RFC 7208, RFC 6376.

What should I test before production?

Submit the form to a third-party mailbox with a unique subject. Confirm history 250 and Header From. Reply to that message and confirm inbound. Do not cron a 550. Do not invent port 25.

Key takeaways

  • Send website email without Postfix: paid authenticated SMTP, not a VPS listener.
  • Copy host and port from the dashboard. Do not invent 25.
  • From must be a mapped alias. Visitor From is spoofing.
  • Exclusive inbound MX so replies return.
  • Free has no send-as. 550 5.7.1 is authorization.
  • Rate-limit the form. Caps are on /pricing.
  • Not a list blast. Not an open relay. Not SOC 2.
  • Prove both directions with a unique subject.

Conclusion and next action

If you want transactional website email without Postfix, keep the VPS a website. Map an alias, cut exclusive MX, pay for send-as, paste dashboard SMTP into env, and prove both directions. MailerZ can authorize From it knows. It will not babysit port 25. Start free for inbound, Solo when the form must leave as the domain.

Ready to send without a mail daemon

Start free for inbound, then Solo when the form sends.

Free receives. Paid send-as copies the dashboard. Sign in if the domain is already there.

Review when SMTP settings or form plugins change, and quarterly otherwise. Author: MailerZ editorial, Secuno LLC.