Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

A lightweight SMTP relay lets an app hand outbound mail (transactional messages, alerts, receipts) to a hosted provider instead of running its own mail server. You have two main arrangements: connect each app directly to a provider’s SMTP endpoint, or point an existing mail server at the provider and let your apps submit to that server. Setup can be quick, but it is not literally instant. Once you have the hostname, credentials, a verified sender, and an open port, the configuration itself usually takes a few minutes. Most delays come from those prerequisites.

Choose a relay model first

The right model depends on how many applications send mail and whether they can speak SMTP with TLS directly. The table compares the three paths covered in the official documentation for Amazon Simple Email Service (SES) and Google Workspace.

Option Best fit How apps connect Documented ports Credentials and sender rules Documented limits
Direct hosted SMTP (Amazon SES) One or a few apps that can use SMTP with TLS Each app connects to the regional SES SMTP endpoint 25, 587, 2587 (STARTTLS); 465, 2465 (TLS Wrapper) Regional SMTP credentials, which are separate from AWS access keys; a verified sender identity Not stated in the AWS SES SMTP setup documentation
Existing mail server relaying to SES Several apps that already submit mail to one local server Apps keep submitting to the local server, which relays to SES Set by your mail server configuration; not stated in the AWS material reviewed SES credentials and verified identity are configured on the mail server Not stated in the AWS SES material reviewed
Google Workspace SMTP relay Organizations already running Google Workspace Apps and devices connect to smtp-relay.gmail.com 25, 465, 587, with SSL/TLS options Relay access is controlled by IP-based authentication configured in the Workspace admin console Up to 10,000 recipients per day per user (Google Workspace Admin Help; publication date not stated)

Check the prerequisites

Gather these items before you touch any application settings:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • The SMTP hostname and port for the region where you will send. For SES, the endpoint is regional, so a credential or hostname from another region will not work.
  • SMTP credentials created for that provider. For SES, these are not your AWS access key ID and secret key, and you cannot substitute one for the other.
  • A verified sender identity, meaning the domain or address the provider allows you to send from. SES requires a verified identity before you send.
  • A client (the app or a mail server) that supports TLS and can be set to the provider’s connection mode.
  • Outbound network access from the host to the endpoint on the port you intend to use.

Set up a direct hosted SMTP connection

Use this path when each application can take SMTP settings directly. The steps below follow the Amazon SES model; other hosted providers use the same pattern with their own labels.

#1 Best Overall
SUPPLYZ Direct Replacement for SERVER 86994 Appliance Sbh-1/6, 2.52 Dia, W/86989, Quad
  • 86994 Sbh-1/6, 2.52 Dia, W/86989, Quad Made Exactly to Fit For Most Top Brand Appliances
  • Satisfaction Guaranteed. Direct Replacement Sbh-1/6, 2.52 Dia, W/86989, Quad Designed for Easy Installation
  • Appliance Sbh-1/6, 2.52 Dia, W/86989, Quad - Meets or Exceeds Original Equipment Manufacturers High Quality Standards. Comes Brand New in Original Retail Packaging
  • SUPPLYZ Appliance Sbh-1/6, 2.52 Dia, W/86989, Quad
  • Check Description for Model Compatibility. Compatible With Most Appliances
  1. Choose the AWS region you will send from and note the SES SMTP endpoint for that region.
  2. In the Amazon SES console, create SMTP credentials for that region. Save the generated username and password immediately, because they are the only values your app will use for authentication.
  3. Verify the sender identity you plan to use. Messages from an unverified sender will be refused.
  4. Select the port and TLS mode (see the port table below). The port and mode must match.
  5. Enter the hostname, port, SMTP username, SMTP password, and TLS setting in the application’s mail configuration. Do not place these values in source code.
  6. Send a test message to an address you control and confirm it arrives. Keep the application’s mail log so you can see the response if delivery fails.

Ports and TLS modes for Amazon SES

Port TLS mode Notes
25 STARTTLS Amazon EC2 throttles port 25 by default. You can request removal of the throttle, switch to another supported port, or use a VPC endpoint.
587 STARTTLS Common submission port; often the simplest choice when port 25 is restricted.
2587 STARTTLS Supported alternative for STARTTLS.
465 TLS Wrapper The connection is encrypted from the first byte, so the client must be set to implicit TLS rather than STARTTLS.
2465 TLS Wrapper Supported alternative for TLS Wrapper.

AWS states that the SES SMTP endpoint requires all connections to be encrypted with Transport Layer Security (TLS). A client set to send plain text will not be accepted.

Route apps through an existing mail server

If several applications already submit mail to one server on your network, you can keep that arrangement and have the server relay outbound messages to SES. AWS documents integrations for common mail transfer agents and says this change can be transparent to existing clients and applications, so the apps themselves usually do not need new credentials.

When this pattern fits

  • Several applications, scripts, or devices already send through one local mail server.
  • You want credentials and sender verification handled in one place.
  • Your mail server is one of the integrations AWS documents.

The trade-off is that the server becomes a shared dependency. If it is down or misconfigured, every application that relies on it stops sending.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Configuration steps

  1. Confirm that your mail transfer agent appears in AWS’s SES integration documentation.
  2. Configure the server’s outbound relay with the regional SES endpoint, the port and TLS mode from the table above, and the SES SMTP credentials.
  3. Confirm the server’s sender address is covered by a verified SES identity.
  4. Point your applications at the local server if they are not already doing so, and send a test message through it.

Use the Google Workspace SMTP relay

Organizations already on Google Workspace can use Google’s SMTP relay service, which Google’s admin documentation recommends for apps and devices. The relay host is smtp-relay.gmail.com. You can use ports 25, 465, or 587 with the SSL/TLS option that matches your client.

Access is controlled differently from SES. Google’s documentation describes IP-based authentication, so you configure the sending IP addresses that are allowed to relay in the Workspace admin settings rather than sharing a username and password with each application. Confirm the exact steps in the current Google Workspace Admin Help article, because the admin layout and options can change.

Google’s documentation says each organization user can relay messages to up to 10,000 recipients per day. This is a limit for the Workspace relay service, not a general SMTP quota, and the page reviewed does not show a publication date. Check the current policy before you plan higher volumes.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Secure the relay

  • Store SMTP credentials in your application’s secret store or in environment-specific secret configuration. Do not commit them to source control.
  • Use TLS on every connection and set the client to the mode that matches the provider’s documented port.
  • Restrict who can read the credentials and rotate them if they are exposed.

If you run Postfix as the relay, be deliberate about TLS policy. Postfix documentation describes TLS as providing certificate-based authentication and encryption for SMTP mail and SASL authentication. Its default opportunistic mode can retry delivery without TLS when a handshake fails. For a provider that requires encryption, a mandatory policy is safer because it makes delivery fail rather than sending mail in plain text. In Postfix this is set through the smtp_tls_security_level parameter, using the encrypt level.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Troubleshoot delivery failures

Work through these checks in order. Each step rules out a class of failure before you move on to the next.

  1. Network reachability. Confirm the host can open a connection to the endpoint on the selected port. A timeout or refused connection usually points to a firewall, a host-level restriction, or the EC2 port 25 throttle. Switch to 587 or 2587, request removal of the throttle, or use a VPC endpoint.
  2. TLS mode. A handshake failure often means the port and mode do not match, such as STARTTLS settings on port 465. Match STARTTLS to 25, 587, or 2587, and TLS Wrapper to 465 or 2465.
  3. Credentials. A missing-authentication or login error usually means the app is using the wrong secret, most often an AWS access key instead of SMTP credentials, or SMTP credentials from a different region.
  4. Sender authorization. A rejected sender usually means the From address is not covered by a verified identity.
  5. Provider permissions. If the earlier checks pass, review the account’s permissions and any sending restrictions in the provider console, including region-level settings.

Keep the server or application log from each attempt. The provider’s response code and message are usually more specific than the application’s generic error.

Quick Recap

Bestseller No. 1
SUPPLYZ Direct Replacement for SERVER 86994 Appliance Sbh-1/6, 2.52 Dia, W/86989, Quad
SUPPLYZ Direct Replacement for SERVER 86994 Appliance Sbh-1/6, 2.52 Dia, W/86989, Quad
86994 Sbh-1/6, 2.52 Dia, W/86989, Quad Made Exactly to Fit For Most Top Brand Appliances; SUPPLYZ Appliance Sbh-1/6, 2.52 Dia, W/86989, Quad
$137.00

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.