# SMTP settings

> Reference for the Emailit SMTP relay, covering host, ports and TLS modes, authentication, From address rules, message size, rate limits and password rotation.

Use these settings to connect an application, framework or device to the Emailit SMTP relay. Every value here applies to all plans.

## Server and credentials

| Setting | Value |
| --- | --- |
| Host | `smtp.emailit.com` |
| Port | `587` (recommended). See [Ports and encryption](#ports-and-encryption). |
| Encryption | STARTTLS on 587, 2525, 2587 and 25. Implicit TLS on 465. |
| Authentication | `AUTH PLAIN` or `AUTH LOGIN` |
| Username | `emailit` |
| Password | An [API key](/docs/developers/api-keys/) from your workspace, starting with `secret_` |

Each API key's page in **Email API → API Keys** shows these values on its **SMTP Info** card.

## Ports and encryption

| Port | Encryption | When to use it |
| --- | --- | --- |
| `587` | STARTTLS | The default for applications. Use it unless your network blocks it. |
| `465` | Implicit TLS | When your client only offers "SSL", or requires TLS from the first byte. |
| `2525` | STARTTLS | When your host or network blocks 587, which some hosting and cloud providers do. |
| `2587` | STARTTLS | A second alternative when 587 and 2525 are both blocked. |
| `25` | STARTTLS | Server-to-server relaying. Many ISPs and cloud providers block outbound port 25, so prefer 587. |

STARTTLS ports start in plain text and upgrade to TLS after the `STARTTLS` command. Port 465 is encrypted from the start. Match the mode to the port: implicit TLS on 587, or STARTTLS on 465, fails during the handshake.

> **Require TLS in your client:** The relay offers TLS on every port but doesn't force it. If your client is set to "no encryption", it sends your API key in plain text. Always turn on STARTTLS or TLS, and connect to `smtp.emailit.com` by name so the certificate matches.

## Authentication

- **Methods.** `AUTH PLAIN` and `AUTH LOGIN`. `CRAM-MD5` isn't supported.
- **Username.** Use `emailit`. Emailit identifies the workspace from the password alone, so the username isn't checked.
- **Password.** A complete API key. **Full Access** and **Sending Only** keys both work. A **Sending Only** key restricted to one domain can only send mail whose From address is on that domain.
- **Without logging in.** The relay accepts the connection, but rejects your recipients with `530 Authentication required`.

A wrong, deleted or regenerated key returns `535 Authentication failed`.

## From address rules

Emailit decides which sending domain a message uses from its `From` header, not from the envelope sender (`MAIL FROM`).

- **Verified domain.** Every address in the `From` header must be on a verified sending domain of the workspace. Otherwise the message is rejected with `530 From/Sender domain is not verified for this workspace`.
- **Exact match.** Domains are compared without regard to case, but subdomains are separate domains: to send from `alerts@mail.acme.com`, verify `mail.acme.com`.
- **Restricted keys.** With a key restricted to one domain, a From address on any other domain is rejected with `530 API key is restricted to sending domain`.
- **Paused domains.** If [sending health](/docs/deliverability/sending-health/) paused the domain, messages are rejected with `550 Sending from this domain is paused`.
- **Envelope sender.** The `MAIL FROM` address isn't checked. Emailit replaces it with a bounce address on your domain's return-path subdomain, so bounces come back to Emailit.

## Message size

The maximum message size is **40 MB**, measured on the message as transmitted, including encoded attachments. Base64 encoding makes attachments about a third larger. The relay doesn't announce the limit with the `SIZE` extension, so a client only finds out after it sends the message: the reply is `552 Message too large (maximum size 40MB)`.

There's no fixed limit on the number of recipients per message.

## Rate limits

SMTP and the Email API share one set of sending limits per workspace. New workspaces start with **2 messages per second** and **5,000 messages per day**. The daily count resets at midnight UTC.

Over SMTP, the unit is one transaction: one message, however many recipients it has. Emailit checks the limits when your client sends `MAIL FROM`, and counts the message toward the daily limit once it's accepted. When you're over a limit, the reply is a temporary `452`, and most clients retry later:

```text
452 4.4.5 Messages per second limit exceeded (3/2)
452 4.5.3 Daily message limit exceeded (5000/5000)
```

Pro and Business workspaces get automatic increases based on sending health. Any workspace can ask for more from the **Sending Limits** card on the dashboard home page. See [Limits](/docs/limits/).

## Sandbox mode

Until your workspace has [production access](/docs/workspaces/production-access/), it can only send to the account email addresses of workspace members. Other recipients are rejected when your client sends `RCPT TO`:

```text
550 Unverified workspaces can only send to workspace members' account emails. Blocked recipient: ada@example.com.
```

## Credits

Each recipient costs 1 credit. Over SMTP, credits are charged when Emailit processes each email, not when the relay accepts the message. If the workspace runs out, the relay still accepts the message, but the emails are **held**. Top up your [credits](/docs/billing/credits/), then [retry](/docs/email-api/retry-and-forward/) the held emails.

## Rotate the SMTP password

The SMTP password is an API key, so rotating it means replacing the key. To switch without interrupting mail, create a new key first:

1. **Create a key.** In **Email API → API Keys**, select **Add API key**, give it a name such as `SMTP – web app` and copy the key. It's shown only once.

2. **Update your applications.** Replace the SMTP password everywhere the old key is used, and restart or redeploy them.

3. **Check the new key.** Send a test message, then confirm in **Email API → Logs** that SMTP requests use the new key and the old one has no recent requests.

4. **Delete the old key.** Open the old key and select **Delete**.

If a key has leaked, open it and select **Regenerate** instead. The old secret stops working immediately, so every application that uses it fails with `535` until you update it. You can also regenerate with [Regenerate an API key](/docs/api-reference/api-keys/regenerate/).

## Framework settings

**Node.js**

```javascript title="mailer.js"
import nodemailer from 'nodemailer';

export const transporter = nodemailer.createTransport({
  host: 'smtp.emailit.com',
  port: 587,
  secure: false,      // STARTTLS; use true only with port 465
  requireTLS: true,   // never send the key unencrypted
  auth: { user: 'emailit', pass: process.env.EMAILIT_API_KEY },
});
```

**Python**

```python title="settings.py"
import os

EMAIL_BACKEND = "django.core.mail.backends.smtp.EmailBackend"
EMAIL_HOST = "smtp.emailit.com"
EMAIL_PORT = 587
EMAIL_USE_TLS = True  # STARTTLS; use EMAIL_USE_SSL with port 465 instead
EMAIL_HOST_USER = "emailit"
EMAIL_HOST_PASSWORD = os.environ["EMAILIT_API_KEY"]
DEFAULT_FROM_EMAIL = "Acme <hello@acme.com>"
```

**PHP**

```bash title=".env"
# Symfony Mailer: STARTTLS is used automatically on port 587
MAILER_DSN=smtp://emailit:secret_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx@smtp.emailit.com:587
```

For step-by-step setup in specific frameworks and platforms, see [Laravel](/docs/frameworks/laravel/), [WordPress](/docs/frameworks/wordpress/), [Rails](/docs/frameworks/rails/) and the other [framework guides](/docs/sdks/).

## Related

- [SMTP relay overview](/docs/smtp/)
- [SMTP headers and replies](/docs/smtp/headers/)
- [SMTP troubleshooting](/docs/smtp/troubleshooting/)
- [API keys](/docs/developers/api-keys/)

---
Source: https://emailit.com/docs/smtp/settings/
