# Why does my SMTP connection time out?

> Fix SMTP connections to smtp.emailit.com that hang or time out, usually because your network or cloud provider blocks port 25.

Use this article when your application can't open a connection to the Emailit SMTP relay at all. If the connection opens but you get an error code, see [SMTP troubleshooting](/docs/smtp/troubleshooting/) instead.

## Symptoms

- Your mail library reports `ETIMEDOUT`, `Connection timed out`, `Connection refused` or `Could not connect to SMTP host`.
- The client hangs for 30 seconds or more before failing, and nothing appears in **Email API → Logs**.
- The same settings work from your laptop but fail from a server, container or serverless function.

## Cause

The connection is blocked before it reaches Emailit. Common reasons:

- **Port 25 is blocked.** Many hosting and cloud providers (for example AWS, Google Cloud, Azure and DigitalOcean) block or throttle outbound port 25 by default to fight spam. Residential ISPs often do the same.
- **Other submission ports are blocked too.** Some providers also block 465 and 587 on new accounts.
- **An egress firewall** or security group only allows specific destination ports.
- **The host name is wrong.** The relay is `smtp.emailit.com`.

Emailit listens on these ports:

| Port | Encryption | When to use |
| --- | --- | --- |
| 587 | STARTTLS | Recommended default |
| 465 | Implicit TLS | When your client prefers TLS from the first byte |
| 2525 | STARTTLS | When 25 and 587 are blocked |
| 2587 | STARTTLS | When 25 and 587 are blocked |
| 25 | STARTTLS | Only if nothing else is available |

## Fix

1. **Switch to port 587.** Set the host to `smtp.emailit.com`, the port to `587` and enable STARTTLS. Port 25 is rarely the right choice for an application.

2. **Test the port from the machine that sends.** Run the check on the server itself, not on your laptop.

```bash
nc -vz smtp.emailit.com 587
nc -vz smtp.emailit.com 2525
```

   On Windows, use `Test-NetConnection smtp.emailit.com -Port 2525` in PowerShell. A working port reports a successful connection (`TcpTestSucceeded : True` in PowerShell). A blocked port times out.

3. **Use 2525 or 2587 if 587 is blocked.** Both offer STARTTLS and are rarely filtered. Keep your client's STARTTLS setting on.

4. **Open the port in your firewall.** Allow outbound TCP to `smtp.emailit.com` on the port you chose, in your security group, network ACL or container network policy.

5. **Ask your provider to unblock port 25 only if you must use it.** Most providers have a request form. Moving to 587 or 2525 is faster.

6. **Consider the HTTP API.** If your platform blocks SMTP entirely, send through the [Email API](/docs/email-api/send-email/) over HTTPS on port 443. See [API or SMTP?](/docs/get-started/api-or-smtp/).

Once the connection works, every message you submit appears under **Email API → Logs** with the source **SMTP**. If the connection now opens but the handshake fails, see [Why do I get TLS errors when connecting to SMTP?](/docs/kb/smtp-tls-errors/). For every setting in one place, see [SMTP settings](/docs/smtp/settings/).

## Still stuck?

[Contact support](/contact/) or ask in [Discord](https://discord.emailit.com). Include the port you tried, where your app runs (provider and region) and the output of the `nc` or `Test-NetConnection` check.

---
Source: https://emailit.com/docs/kb/smtp-connection-timeout-port-25/
