Skip to content
Mail servers and blacklists

Fix mail servers that refuse connections

Why a domain's mail servers don't accept connections on port 25, what it means for incoming email, and how to fix it or remove dead MX records.

By the Domain Health Hub team · Updated

In short
  • Other mail servers deliver to the hosts in the MX records on port 25. We couldn't connect to some or all of them.
  • If none answer, incoming email is failing. If only some don't, delivery is slower and less reliable.
  • The usual causes are an old backup server, a cancelled provider still in DNS, or a firewall.

What this means

For each mail server in the MX records (up to the 10 most preferred), we try to open a connection on port 25, the port other mail servers deliver on, with a short timeout of a few seconds. The connection was refused or timed out on every server, or on some of them.

Why it matters

If no mail server answers, senders queue the email and retry, usually for a few days, then bounce it. Nobody at the domain sees anything until people complain their email bounced. If only some servers fail, email still arrives through the others, but senders waste time on the dead ones, and a forgotten backup server can accept mail and never pass it on.

How to confirm it

From a network that allows outgoing port 25 (many home and office connections don't), run nc -v mail.example.com 25 or telnet mail.example.com 25. A working server replies with a line starting 220.

How to fix it

  1. Compare the MX records with the current email provider. After a move to Microsoft 365 or Google Workspace, the old host's MX records are often left behind. Delete any that belong to a service the client no longer uses.
  2. Check the account is active. A cancelled or unpaid email service stops accepting connections but leaves the DNS in place.
  3. For a server you run, check the mail service is running and the firewall (and any cloud security group) allows inbound port 25 from anywhere.
  4. Check each MX host resolves to the right address. A server that changed IP while DNS kept the old one looks exactly like a dead server.
Microsoft 365
One MX record, as shown under Settings > Domains in the admin centre.
Google Workspace
One MX record: smtp.google.com at priority 1.

Domain Health Hub repeats this check every day and alerts you by email or webhook when a mail server stops answering.

Questions

Could this be a temporary blip?

Yes, which is why it's worth confirming. A server that's down for an hour is a nuisance; one that's down at every daily check is almost always a dead or blocked server.

Do I need a backup MX?

Rarely now. Sending servers queue and retry for days, and hosted providers run their own redundancy. A backup MX that isn't maintained causes more trouble, including spam that bypasses the main server's filtering.

Hear about it the day it breaks.

Daily checks on every client domain, alerts when something changes, and a monthly report card your clients will understand.

Start 28-day free trial