Send via SMTP Email Relay

Troubleshoot Email Relay

Go from symptom to cause in order, for failures to connect, rejected authentication, and mail that sends but never arrives.

Every table starts from the symptom you see. Upper rows are more common than lower ones, so read down and stop at the first row that matches.

First: is your software actually going through the relay

Answer this before anything else.

Open Email Relay → Stats & logs, switch to the Logs tab, and look for the row matching the message you just sent.

The Email Relay Stats & logs screen on its Statistics tab: a Statistics / Logs switch at the top right, a date range selector, four cards for Total sent, Delivered, Bounced and Complained, a daily activity chart, and the Bounces by type block

The screen opens on the Statistics tab, figures for the whole domain. The per-message table is on the Logs tab.

The logMeansWhat to do next
Has a rowthe software went through the relayRead that row's status, then go to Sends but does not arrive
Has no rows at allthe software is still sending the old way; the configuration has had no effectRestart the software — many need it to load the new configuration. Also check whether it has several mail profiles and you edited the wrong one

No rows is the most misdiagnosed case: people hunt for a fault inside the relay when the relay never received anything.

The send is rejected

SymptomCauseFix
Authentication rejectedThe username field holds an email address. This is cause number one, and the error looks identical to a wrong passwordThe username must be exactly apikey
Authentication rejectedThe password field holds your console login passwordThe password is the SMTP key, in the form cfr_...
Authentication rejectedThe key has been revokedThe SMTP Keys table marks unusable keys Revoked; create a new one
Authentication rejectedThe key is pinned to an IP and your server's IP changed — the key is still right but can no longer sendCheck the IP whitelist column and update the IP
Authentication rejectedThe key was truncated when storedCheck the length of the string your software actually sends
Sender address rejectedThe domain in From is not active yetPublish the relay sending domain records
Sender address rejectedThe SMTP key is bound to a different domain; a key can only send from its ownUse the key bound to the domain in From
Sender address rejectedA typo in the domain in FromCorrect From

Cannot connect

You never reach the authentication stage — the software cannot open a connection.

CauseFix
Ports blocked on your side; many hosting providers block outbound mail ports by defaultTry both 587 and 465. If both fail, blocking is almost certain
Wrong encryption mode — mixing the pairs hangs the connection or drops it midwayPort 587 uses STARTTLS, port 465 uses implicit SSL/TLS
An internal firewallTry from a different network to isolate it

Sends but does not arrive

There is a row in the log, so the relay accepted it.

Check, in orderIf this is the cause
The recipient's junk folder — the most skipped step and the most often correctRead on to Messages land in junk
The status in the logBounced means the receiver refused it — read the reason alongside it
The suppression listThe message is dropped before leaving the system
The sending domain's DNS recordsMissing signing records let mail go out but get it filed as junk

Messages land in junk

Not a technical fault, so no single button fixes it. The table is ordered by impact.

CauseFix
Missing signing records — one missing row means no signaturePublish all the rows
No _dmarc record, or one that contradicts your sending sourceAdd a _dmarc record that does not contradict your sending source
Still mailing hard-bounced addresses — a high bounce rate is a scored signalDrop those addresses from your send list
Sending large files as direct attachmentsSend a download link instead

Message rejected as too large

The size limit block on the SMTP configuration page states the ceiling for one message, counting attachments after encoding — and the encoded figure is larger than the original file.

The fix is a download link, not compressing the file to fit.

When to contact support

Send these four; they are enough to pull up the exact record:

  1. The sending domain
  2. The approximate time, with the time zone
  3. The recipient address
  4. Your software's error message verbatim, or the status in Stats & logs

Do not include the SMTP key

Nobody needs it to look something up, and sending it means you have to revoke it.