Testing SMTP from a VPS means one authorized submit through MailerZ, not a listener on port 25 and not a loop over users. Copy the dashboard host and port. Send as a mapped alias. Confirm history 250 on a mailbox that is not the sending Gmail. Then stop. Delete the script. Free has no send-as. A for-loop is bulk. A purchased list is abuse. Warm-up is out of scope.
Quick answer for test smtp from vps
Pay for send-as. Put dashboard SMTP in env on the VPS. Send one message. Read history. Product path: send and reply, docs, features. IETF RFC 5321 — Simple Mail Transfer Protocol. Quote ImprovMX SMTP only as a competitor hop—do not copy ports. Confirm pricing. Solo $40/yr. Starter $8/$80. Business $19/$190. Agency $39/$390. 550 5.7.1 is auth. No inbox SLA. Not SOC 2.
Helpful tests are boring: people-first content. CAN-SPAM: US Federal Trade Commission — CAN-SPAM compliance guide if someone “tests” a list.
The user problem and the decision criteria
Engineers want to know the VPS can talk SMTP before a launch. The useful proof is one 250. The useless proof is ten thousand 250s to strangers.
| Question | If yes | If no |
|---|---|---|
| One unique recipient you control? | That can be a test. | You are mailing a set. |
| Is port 25 listening? | Close it. You became an MTA. | Good. Submit only. |
| Will a cron fire this? | Not a test. Disable it. | Good. |
| Purchased or scraped addresses? | Stop. That is abuse. | Good. |
| Free plan? | You will 550. Upgrade first. | Copy dashboard values. |
Technical mail flow
The VPS authenticates to MailerZ and offers one envelope. MailerZ 250s or 550s. The recipient’s MX is their problem. Your VPS must not accept internet mail on 25. That path is how open relays start—see the later open-relay article.
Self-send hides failures. Third mailbox. IETF RFC 7208 — Sender Policy Framework (SPF) and IETF RFC 6376 — DomainKeys Identified Mail (DKIM) apply once you send for real. Leftover MX is an inbound ticket if you also test replies.
Step-by-step setup and decision path
Map From and pay for send-as
Alias exists. Exclusive MX if replies. Copy dashboard SMTP.
Env on the VPS
No secrets in the script you will paste in Slack.
Send one unique subject
Third mailbox. Read history 250. Header From intact.
Confirm 25 is closed
ss or your cloud SG. You submit out. You do not listen.
Delete or disable the script
A leftover test file becomes tomorrow’s cron.
If 550, stop
Fix plan or From. Do not retry in a loop.
Failure modes and proof
| What you see | Likely cause | Proof |
|---|---|---|
| 550 5.7.1 | Free or bad From | Plan and alias |
| Timeout | Wrong port or 25 blocked outbound | Dashboard port |
| Many 250s | You looped | Stop the process |
| Empty history | Never reached MailerZ | Env host typo |
| 25 open inbound | You installed an MTA | Close the listener |
Proof is one history row, a closed 25, and no leftover script. Agencies: test per client credential, not one shared user.
MailerZ workflow and product boundary
Authenticated SMTP plus inbound MX. Not Postfix. Not IMAP. Not an open relay. Free: 1 domain, 3 aliases, 14-day store, send-as disabled, SMTP and API disabled. Solo $40/yr. Starter $8/$80. Business $19/$190. Agency $39/$390. Confirm pricing. No inbox SLA. No SOC 2.
Cost, alternatives, and trade-offs
| Choice | What you get | What you give up |
|---|---|---|
| One paid SMTP probe | A 250 you can show | The comfort of a loop |
| Local Postfix “just to test” | A mail server | A closed 25 |
| List vendor seed list | Their job. Quote live | This hop’s AUP |
Time is a line item. One probe costs less than a blocklist Monday. Leftover MX is a different invoice.
One message is the test
Connectivity, AUTH, From authorization, and a 250 are the questions. Ten messages do not answer a new question. They spend the cap and annoy a mailbox.
If you need two directions, send one, then reply to the mapped alias. That is two messages, still not bulk.
Unique subjects let you search Gmail and history. “test” is how you match the wrong row.
What counts as bulk
A for-loop, a CSV, a purchased list, a “warm-up” service, and a cron every minute are bulk or abuse. We will not help design those. Purelymail and others ban warm-up on their sites. We are not a warm-up hop either.
Staging that mails production users is bulk with a typo. Use a sink mailbox.
US Federal Trade Commission — CAN-SPAM compliance guide still applies if you “test” marketing copy to many people.
Delete the proof script
Scripts in /tmp become systemd timers. Delete them. Keep env in the platform secret store for the real app, not in a gist.
Rotate the SMTP password if the test leaked in chat. Two-factor on the destination. Re-query MX after registrar saves if you also cut inbound.
IPv6 on the VPS is not a reason to open 25. Submit on the dashboard port.
Night operators who “just send to the whole staging table” recreate bulk. Write “one recipient” on the ticket.
If a second operator needs the order, send this page plus the Postfix and notifications articles. One 250. Closed 25. No loop. Paid send-as. Mapped From.
The artifacts that close test smtp from vps are a history 250, a closed listener, and a deleted script. Everything else is a campaign you called a test.
Field notes for a VPS SMTP probe
What the VPS is allowed to be
A VPS that tests SMTP is a client. It opens a connection to the MailerZ dashboard host, authenticates, offers one envelope, and closes. It is not an MTA. It does not listen on port 25. It does not accept internet mail. The moment you install Postfix “just to see if mail works,” you created a different product: a server that strangers can find. That is how open relays start. Close the listener. Keep the submit path.
Cloud security groups that leave 25/tcp inbound open are not a convenience. They are an invitation. Check ss, netstat, or the provider firewall after the image boots. If something is listening, stop it before you copy SMTP secrets onto the box. A closed 25 and a paid dashboard pair are the whole topology.
AUTH is hop zero
Could-not-authenticate is not a destination 550 and not a greylist 421. It means the VPS never became a MailerZ client. Wrong host, wrong port, STARTTLS versus implicit TLS mix-up, user that is not the dashboard pair, or a Free plan that has no send-as. Fix the pair. Do not retry in a loop. A loop of AUTH failures looks like abuse to every hop that can see you.
Copy host, port, and TLS mode together from the dashboard. Do not invent 587 because a blog said 587. Do not invent 465 because a different blog said 465. The product page is the source. ImprovMX SMTP pages are a competitor hop — cite them nofollow if you compare, do not copy their ports onto this product.
One unique subject is searchable evidence
Subject lines that say test or smtp are how you match the wrong history row next week. Use a unique string: the hostname, the UTC minute, and a nonce. Search that string in MailerZ history and in the third mailbox, including spam. Header From must be the mapped alias, not the linux user@hostname the VPS invented. If Header From is root@box, you did not send as the domain.
The third mailbox cannot be the same Gmail you use for Send mail as. Self-send short-circuits. Use a personal account you do not send from, or a second provider. That is the only proof you can show a launch channel.
550 5.7.1 is authorization, not a folder
Free has no send-as. Unmapped From has no send-as. Catch-all does not mint a From. Unauthorized is SMTP 550 / 550 5.7.1. That is honest. Upgrade to Solo at forty dollars a year if the domain From must travel, or stay inbound-only. Confirm live numbers on the pricing page. Solo, Starter, Business, and Agency raise outgoing and hourly caps. They do not buy inbox placement and they do not bless a for-loop.
If AUTH succeeded and the destination later 421’d, that is a different ticket. Read the class. Do not open port 25 because Gmail greylisted once. See the 421 article if you need that class.
Env files and the script you will regret
Put the password in the platform secret store or a root-only env file that is not in git. A test script in /tmp becomes a systemd timer after a reboot you forgot. Delete the script after the 250. If the password appeared in Slack, rotate it. Do not mail the secret to support with the ticket. Send the 550 line, the timestamp, and the Message-ID.
IPv6 on the VPS is not a reason to listen on 25. Submit on the dashboard port. If outbound 25 is blocked by the cloud — common — that is why you use the documented submission port, not a local relay.
Bulk dressed as a test
A for-loop over users, a CSV, a purchased list, a warm-up vendor, and a cron every minute are not tests. They are campaigns or abuse. MailerZ is not a blaster. CAN-SPAM still applies if you “test” marketing copy to many people. Staging that mails production users is bulk with a typo. Use a sink mailbox you control.
Ten 250s do not answer a new connectivity question. They spend the monthly outgoing cap and train a mailbox to mark you as noisy. Two directions — one outbound, one reply to the mapped alias — are still two messages, not a list.
Agencies and shared boxes
Test per client credential. A shared SMTP user across clients couples their hourly caps and their incident blast radius. Isolate. Offboard means revoke that pair when the client leaves. Agency plan capacity is numeric. It does not replace a named From or a closed listener.
If two engineers need the order, write it on the ticket: paid plan, mapped From, dashboard host and port, one unique subject, third mailbox, history 250, closed 25, deleted script. That sentence is the whole test.
Inbound leftovers are a different ticket
This page is outbound submit. If you also want to prove replies to the mapped alias, that needs exclusive MailerZ MX and leftovers deleted. Dual MX is leftover, not a hybrid. Empty inbound history after a reply test is leftover Google or a missing alias, not a VPS problem.
Transport still follows RFC 5321. SPF and DKIM apply once you send for real. They are authentication, not encryption. MailerZ does not rewrite Header From. Envelope SRS is inbound. Not SOC 2. Not HIPAA. Not an inbox SLA.
Worked story: a launch engineer left a Python loop in crontab that mailed every staging user every boot. AUTH worked. History filled with 250s. Users reported spam. They killed the cron, rotated the SMTP secret, and kept one probe script that they deleted after the next 250. The VPS never needed port 25. It needed a deleted timer.
Second story: another team used Free and retried 550 for an hour. Nothing in history except rejects. They upgraded to Solo, mapped notify@, sent one unique subject to a third mailbox, and closed the ticket. The hour of retries was not a test. It was a lockout rehearsal.
Operator brief: test SMTP from a VPS is one authorized submit. Paid dashboard pair. Mapped From. Unique subject. Third mailbox. History 250. Closed inbound 25. Deleted script. No loop, list, warm-up, or Postfix. Confirm pricing. Start free for inbound if you also need the domain to receive. Solo when the probe must send as the domain.
Related pages that already exist: send and reply, docs, features, troubleshooting, and pricing. After the 250, keep the unique subject next to the closed-port screenshot. The next argument should not restart at “we need to warm the IP.” MailerZ is not a warm-up hop.
Operator packet for a VPS SMTP test
Write the ticket before you SSH
The ticket should name the plan, the mapped From, the dashboard host and port as a single copied trio, the third-mailbox address, the unique subject pattern, and the person who will confirm inbound 25 is closed. If any of those are missing, you are improvising on a box that can become an MTA by accident. MailerZ Free cannot finish this ticket. Solo at forty dollars a year can. Confirm the live pricing page. Starter, Business, and Agency raise outgoing and hourly caps. They do not bless a loop and they do not buy inbox placement.
Put the cloud project, the image name, and the security-group id on the same ticket. After the 250 you will want to prove the listener stayed closed. A screenshot of ss or the firewall rule with a UTC timestamp is part of the packet. A chat message that says “looks good” is not.
How to read history after the submit
If history is empty, the VPS never reached MailerZ. Check env host typos, outbound firewall on the submission port, and whether you used port 25 because a tutorial said so. If history shows AUTH failure, stop the process. If history shows 550 5.7.1, you are on Free, the From is unmapped, or the secret was revoked. If history shows 250 and the third mailbox is empty, search spam and all mail. Delivered includes junk. Primary is a folder, not an SMTP status.
If history shows 421 at the destination, wait. Do not open a local relay. Do not add leftover Google MX. Temporary deferral is a different article. If history shows destination 550, fix the dest address. Do not retry in a cron.
Images, cron, and configuration management
Golden images that bake in Postfix or a test script will recreate bulk after every autoscaling event. Bake in the env hook, not the probe. Configuration management that copies a script from an old role will do the same. Delete the probe from the image. Keep secrets in the store the platform already has.
Kubernetes CronJobs are crons. Serverless timers are crons. A GitHub Action that mails on every push is a cron with a badge. Write “one recipient” on the workflow or do not ship it. Staging sinks belong in staging credentials.
IPv6, NAT, and shared egress
Many VPS providers NAT many tenants through one egress. That is their network, not a MailerZ warm-up story. You still authenticate. You still send as a mapped From. You still stop at one 250 for the test. Shared egress is not permission to mail a list. If the provider blocks outbound 25, that is expected. Use the dashboard submission port.
IPv6-only guests still submit as clients. They still must not listen on 25. Dual-stack images that open 25 on both families double the accident.
What you tell security and what you do not
You may say: we submit authenticated SMTP to a hop we pay for, From a named identity, with a closed inbound 25. You may not say: we are a mail server, we warmed the IP, we have SOC 2, we guarantee inboxing. Point questionnaires at the security page. Privacy, terms, DPA, and subprocessors are published. Do not invent processors to win a VPS review.
CAN-SPAM still applies if someone pastes a purchased list into the “test.” We will not help design that. Related: why open relays are dangerous, how to use SMTP credentials in env files, and how to test SMTP from Linux with swaks or OpenSSL if the engineer wants a laptop proof before the VPS proof.
Close criteria you can paste
Paid plan. Mapped From. Dashboard trio in env, not in git. One unique subject. Third mailbox including spam. History 250. Header From intact. Inbound 25 closed on the guest and in the security group. Probe script deleted. Secret rotated if it leaked. No cron. No CSV. No warm-up vendor. That is a closed test SMTP from a VPS ticket.
Start free if you also need inbound on the domain. Exclusive MX and leftover delete are inbound work. They are not a substitute for the outbound 250. Sign in if the domain is already there. The register URL is the MailerZ app register path.
More operational notes
A VPS is not a reputation product
Providers sell VPS images with “mail stack included.” That stack is Postfix plus hope. MailerZ send-as is a dashboard identity on a paid plan. Mixing them — local 25 plus hop SMTP — is how you create an open listener and an authorized client on the same box. Keep the client. Delete the stack. If the image cannot boot without a mail daemon, pick another image.
What a 250 does not mean
A 250 means MailerZ accepted the envelope from an authorized client. It does not mean Gmail Primary. It does not mean the destination will never 421 later on a different message. It does not mean you may loop. It does not mean the monthly outgoing cap reset. One 250 closes the connectivity question. Production volume is a capacity plan, not a longer test.
Pair rotation after a leaked gist
Engineers paste env into gists to “show the error.” Rotate the SMTP password the same hour. Revoke the old pair. Update the secret store. Do not leave the leaked pair valid “until the sprint ends.” A leaked pair plus a cron is bulk you did not mean to ship.
Laptop swaks versus VPS proof
A laptop swaks session proves the credentials. A VPS proof proves the guest security group, the image, and the lack of a listener. Do both if you want. Do not treat the laptop 250 as a closed VPS ticket. The guest can still be listening on 25 after a laptop success.
Night notes
Night operators who “just send to the staging table” recreate bulk. Write one recipient on the ticket. Agencies isolate credentials. IPv6 is not a reason to listen. Related swaks and env-file articles exist. After the 250, keep the unique subject next to the closed-port screenshot.
MailerZ remains inbound MX plus authenticated SMTP from Secuno LLC. Envelope SRS only. Header From, Subject, Date, Message-ID, body, and MIME stay intact. Not Google Workspace, not IMAP, not webmail, not an open relay. Unauthorized send is 550 / 550 5.7.1. Leftover MX is a hard stop. Self-send from Gmail to the same Gmail account can hide routing errors. Not SOC 2, not ISO 27001, not HIPAA. Free is one domain, three aliases, one seat, a fourteen-day store, fifty outgoing messages per month, unknown recipients held, and no send-as. Solo is forty dollars per year. Starter is eight monthly or eighty yearly. Business is nineteen or one hundred ninety. Agency is thirty-nine or three hundred ninety. Confirm numbers on the pricing page. Limits are not an inbox-placement promise. Start free at the MailerZ register URL when inbound must be proven first.
FAQ
What is the safest way to handle test smtp from vps?
Send one uniquely titled message through paid MailerZ SMTP using dashboard host and port. From a mapped alias. Confirm history 250 on a third mailbox. Close port 25 on the VPS. Delete the test script. Do not loop users, buy a list, or warm up. Free has no send-as.
Does this require a new mailbox?
No. The third mailbox can be a personal Gmail you do not send from. MailerZ is not IMAP. The VPS is a client, not a store.
Will it work with Gmail or Outlook?
The test recipient can be either. Self-send from the same Gmail is a bad gate. Free cannot send as the domain. 550 5.7.1 is authorization.
What DNS records are involved?
Mapped From needs the alias. Outbound SPF, DKIM, DMARC from the dashboard. Inbound exclusive MX only if you also test replies. Two SPF records permerror. See RFC 5321.
What should I test before production?
This page is the test: one message, one 250, closed 25, no cron. Then the app or form can use the same env. Do not scale the test into bulk.
Key takeaways
- Test SMTP from a VPS: one unique message, then stop.
- Dashboard host and port. Close inbound 25.
- Mapped From. Free has no send-as.
- Third mailbox. History 250. No self-send gate.
- No loops, lists, crons, or warm-up.
- Delete the script. Rotate if it leaked.
- 550 is auth. Leftover MX is inbound.
- Confirm /pricing. Not SOC 2. Not an inbox SLA.
Conclusion and next action
If you need to test SMTP from a VPS, send one authorized message and close the listener. MailerZ can 250 a From it knows. It will not excuse a loop. Start free for inbound, Solo when the probe must send as the domain.
Ready to probe once
Start free for inbound, Solo for one honest 250.
Copy the dashboard. Do not open 25. Sign in if the domain is already there.
Review when VPS images or SMTP settings change. Author: MailerZ editorial, Secuno LLC.