Skip to main content
← Back to glossary
Email deliverability

Open relay

Was ist Open relay?

Dieser Eintrag liegt derzeit nur auf Englisch vor.

An open relay is an SMTP mail server that accepts and forwards email for anyone without requiring authentication or any established relationship between sender and server. Spammers abuse open relays to hide the true origin of bulk mail, which is why open relays are blocklisted within days of discovery, and any legitimate mail that shares the relaying server inherits that damage. Modern mail servers ship as closed relays by default, forwarding only for authenticated users and explicitly authorized sending domains.

More detail

Open relays are the reason spam became an industrial-scale problem. Through the 1990s most mail servers relayed for anyone by default, and spam operations maintained harvested lists of them to anonymize their sends. Blocklist operators still probe for relay behavior today, and a server caught relaying can land its whole IP range on blocklists such as Spamhaus, rejecting or spam-folding mail from every sender on that server until the misconfiguration is fixed and the listing cleared.

The open-relay problem is also the reason modern sender authentication exists. SPF, DKIM, and DMARC let a receiving server answer 'is this sender authorized?' for every message, which is the same question a closed relay asks before it forwards. Operators keep their own servers closed by requiring authentication on the submission ports, rejecting unauthenticated relay attempts for foreign domains, and publishing SPF records so receivers can verify authorization on their behalf.

Häufige Fragen

Why is an open relay a security problem?
It lets anyone send mail that appears to originate from the relay's IP address and domain, so spammers use open relays to launder bulk mail and phishing. The relay's operator absorbs the complaints and the blocklistings, while legitimate senders on the same server see their mail rejected or spam-folded until the relay is closed.
How do I check whether a mail server is an open relay?
Probe it the way a blocklist operator would: open an SMTP connection from an outside network and attempt an unauthenticated send to a foreign domain. A correctly configured server rejects the recipient with a relay-denied or authentication-required reply; a server that accepts and queues the message is relaying openly. Public relay-test services run exactly this probe if you prefer not to script it.
What is the difference between an open relay and a legitimate mail relay?
Authorization. A legitimate relay forwards only mail it is responsible for: submissions from authenticated users, outbound mail for domains it hosts, or sends from IP ranges and domains it has explicitly authorized through SPF. An open relay performs none of those checks, which is what makes it abusable and blocklistable.

Build it on Orbit

Voice, messaging, email, video, and AI agents on one platform and one pay-as-you-go bill. Start free — no credit card required.